A Five-Year-Old Firmware Bug Just Cost Bitcoin Holders 30 Million. Your Business Hardware Has the Same Problem.
The COLDCARD hardware wallet breach stole 30M in Bitcoin from 'secure' devices. The lesson isn't about crypto — it's about what happens when businesses trust hardware they've never verified.
In late July 2026, something that shouldn't have been possible happened: attackers stole more than 30 million in Bitcoin from hardware wallets — devices specifically designed so that couldn't happen.
The COLDCARD wallets weren't hacked through phishing. No employee clicked a bad link. No password was guessed. The private keys were never transmitted over the internet. The devices sat in people's homes, completely air-gapped, doing exactly what they were supposed to do.
And yet, within 41 minutes of the first attack wave, over 1,000 Bitcoin addresses had been drained. By the time multiple attacker groups finished working through the exposed wallets, the confirmed theft exceeded 30 million across more than 7,300 addresses.
The cause? A firmware bug that shipped in March 2021 and sat undetected for more than five years.
The Bug That Nobody Caught
Here's what happened at the technical level, explained without the jargon.
When you set up a hardware wallet, the device generates a seed phrase — essentially the master key to all your funds. For that key to be secure, the randomness used to generate it must be genuine, unpredictable hardware randomness. That's the whole point of a dedicated hardware security chip.
The COLDCARD firmware update in March 2021 introduced a flaw in that process. Instead of drawing randomness from the hardware chip, the code quietly fell back to a software-based alternative seeded from predictable values — the device's serial number and clock registers. The hardware chip was still present. The device still appeared to be working correctly. But the randomness it was producing was far weaker than anyone realized.
On affected Mk2 and Mk3 models, effective entropy dropped from 128 bits to roughly 40 bits. On Mk4, Mk5, and Q models, it dropped to 72 bits. The difference sounds technical, but the practical result is stark: a seed that should require astronomical computing power to guess becomes solvable in hours on ordinary hardware.
A developer flagged a related issue to Coinkite, the manufacturer, in May 2025. The vulnerability wasn't addressed before attackers discovered it independently and built automated tooling to exploit it at scale.
When the first sweep hit on July 30, 2026, Galaxy Research mapped 1,196 wallet addresses drained in 41 minutes. At least a dozen separate attacker groups eventually exploited the same underlying weakness. Coinkite shipped a patch within 24 hours — but updating firmware doesn't fix seeds that were already generated under the flawed code. Every wallet created on vulnerable firmware remains compromised regardless of what version runs on the device today.
This Isn't a Crypto Story. It's a Business Story.
I'm not writing this because your company holds Bitcoin in hardware wallets — though if you do, migrate those funds immediately.
I'm writing this because every organization I work with has the equivalent of a COLDCARD vulnerability somewhere in their environment. They just don't know it yet.
Think about the hardware your business trusts without question:
- Network switches and routers from vendors who shipped firmware updates years ago and never pushed a forced upgrade - Industrial control systems and OT equipment running software versions that haven't been reviewed since installation - Security cameras and IoT devices with embedded firmware that was current at purchase and untouched since - Endpoint devices — laptops, workstations — that your IT team tracks for software patches but rarely audits at the firmware level - Physical security systems that run on embedded hardware with software update cycles measured in years, not months
All of these sit in your environment doing exactly what they appear to be doing. Most of them have never had their firmware independently verified. Some of them are running code that was written years ago and reviewed by a handful of engineers at a vendor you may barely remember approving.
The COLDCARD breach didn't happen because the devices were cheap or poorly designed. COLDCARD is considered a premium hardware wallet — the kind serious security-conscious users trust specifically because it's not a cheap consumer product. The vulnerability existed precisely because a subtle flaw in one firmware update introduced a weakness that passed all normal quality checks and appeared in open-source, publicly reviewable code for five years before anyone weaponized it.
The Three Gaps That Made This Possible
The COLDCARD breach illustrates three gaps that exist in most organizations' security postures:
Gap 1: Firmware is treated as infrastructure, not software. Most organizations have mature processes for patching operating systems and applications. Firmware updates — for routers, switches, cameras, printers, embedded systems — often fall into a different category that nobody explicitly owns. IT assumes OT handles it. OT assumes IT handles it. Neither tracks it systematically.
Gap 2: Hardware trust is assumed, not verified. When you buy a security appliance, a managed switch, or an IoT sensor from a reputable vendor, you assume the firmware it ships with has been thoroughly audited. Most of the time, that assumption is reasonable. But 'most of the time' is not a security posture. Vendors make mistakes. Supply chains get compromised. Bugs get introduced in updates. The COLDCARD flaw sat in open-source code for over five years — publicly visible, but not scrutinized.
Gap 3: No patch means no fix, but nobody knows. In the COLDCARD case, updating firmware doesn't fix wallets that were already compromised. The same dynamic plays out in enterprise hardware: some vulnerabilities affect data or configurations that were created before the patch, and patching the device doesn't undo the exposure. Organizations rarely have visibility into what state their hardware was in historically — only what it's running right now.
Three Questions Your Business Should Be Asking
You don't need to audit every device in your environment this week. But you should be able to answer these three questions:
1. Do you have an inventory of your hardware and the firmware versions running on it? Not just servers and workstations — routers, switches, firewalls, industrial systems, cameras, printers. If you can't enumerate what you have and what version it's running, you can't know your exposure when a firmware vulnerability is disclosed.
2. Who is responsible for firmware updates in your organization, and what's the process? If the answer is unclear, that's the gap. Assign explicit ownership. Define a process for evaluating firmware advisories and deploying updates — separate from your software patch process if needed, but equally systematic.
3. Do your vendor contracts include security advisory notification? When a hardware vendor discovers a vulnerability in shipped firmware, do you find out immediately, or do you read about it on BleepingComputer three months later after victims start coming forward? Your procurement and vendor management process should include requirements for timely security disclosure.
The Lesson From 30 Million
The people who lost Bitcoin in the COLDCARD breach trusted their hardware. They were right to trust it — it was genuinely well-designed for its purpose. But trust placed in a device you never independently verify is really just faith.
Your business can't verify every line of firmware code your vendors ship. Nobody can. But you can establish systematic oversight: know what you have, know what's running on it, know who's responsible for keeping it current, and know when vendors disclose problems with what you've already deployed.
The vulnerability that drained 30 million in 41 minutes wasn't exotic. It was a subtle randomness flaw in a software library, introduced in a single firmware update, reviewed by nobody with adversarial eyes, and left in place for five years.
The next firmware vulnerability affecting your business is already out there. The question is whether you'll know about it before the attackers do.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.