BTC ETH SOL BNB XRP Fear & Greed
AltcoinGordon
News

Coldcard Reports Differ on Whether $114M Was Stolen

crypto.news and CryptoBriefing both cover Coldcard's firmware fix but disagree on whether an actual theft of Bitcoin occurred.

Stock photograph illustrating: Coldcard Reports Differ on Whether $114M Was Stolen
Stock photograph, chosen to illustrate this story. The photographer is credited on the image.

crypto.news and CryptoBriefing both cover Coldcard's firmware fix but disagree on whether an actual theft of Bitcoin occurred.

What all sources agree on

  • Coldcard released firmware versions 5.6.1 for Mk4 and Mk5 devices and 1.5.1Q for Q devices.
  • The update requires users to supply their own entropy (key presses, dice rolls, or coin flips) during seed generation.
  • The underlying flaw traces to a firmware change from March 2021 (version 4.0.1) affecting how seeds were generated.
  • Affected users are advised to create new wallets and migrate their Bitcoin rather than reuse old seeds.
  • The flaw reduced entropy on older Mk2/Mk3 units to roughly 40 bits, with lesser reductions on later models.
  • The firmware also addresses other areas including transaction signing and backup procedures.

Where the reports disagree

1Whether a theft of funds actually occurred

which addressed a flaw in how some versions of its firmware generated wallet seed phrases.

crypto.news

attackers exploited a seed-generation vulnerability that drained approximately 1,816 BTC, worth roughly $114M to $116M, from affected wallets.

CryptoBriefing

What would settle it: On-chain transaction records showing outflows from affected Coldcard wallet addresses, or a company statement confirming or denying stolen funds.

2Timeline and existence of an exploitation window before the hotfix

Coldcard said in an Aug. 20 post that the latest release followed three weeks of review after its July 31 emergency fix, which addressed a flaw in how some versions of its firmware generated wallet seed phrases.

crypto.news

Attackers began exploiting the weakness on July 30, 2026. Coinkite responded the next day with an urgent hotfix on July 31, but the damage was already substantial.

CryptoBriefing

What would settle it: A public incident report or security disclosure from Coinkite detailing whether active exploitation occurred between July 30 and July 31, 2026.

What to make of it

Treat the firmware versions, the entropy fix, and the migration advice as established; do not treat the $114M/1,816 BTC theft figure as confirmed until Coinkite or on-chain data verifies it.

Treat the firmware versions, the entropy fix, and the migration advice as established; do not treat the $114M/1,816 BTC theft figure as confirmed until Coinkite or on-chain data verifies it.