View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft

๐Ÿšจ ACTIVE EXPLOITATION

  • Coldcard Hardware Wallet Flaw Linked to $70M Bitcoin Theft in 41 Minutes
    A firmware flaw in Coldcard hardware wallets enabled theft of over $70 million in Bitcoin.

    • Applies to Coldcard Bitcoin-only hardware wallets by Coinkite, including Mk2, Mk3 (4.0.0-4.1.9), Mk4, Mk5 (pre-5.6.0), and Q (pre-1.5.0Q) models
    • Vulnerability caused by March 2021 firmware error routing seed generation to deterministic software PRNG instead of hardware RNG
    • Attackers can reproduce seed outputs offline by constraining device UID, timer state, and RNG call history to derive victim addresses
    • Galaxy Research mapped theft of 1,196 Bitcoin addresses totaling 1,082.65 BTC (~$70.2M) drained in 41 minutes on July 30, 2026
    • Coinkite released emergency firmware July 31 but it does not repair existing compromised seeds; affected users must generate new seeds
      ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via The Hacker News
  • Hackers Target 30+ Minnesota Water Systems in 48-Hour Cyberattack
    Over 30 Minnesota water systems were hit by a coordinated cyberattack in 48 hours.

    • Targets: More than 30 Minnesota community water systems including Braham, Maple Plain, Plymouth, South St. Paul
    • Vulnerabilities: Water treatment control systems managing chemical dosing, pressure, and distribution
    • Attack impact: At least one plant shut down; emergency statewide response activated
    • Attack nature: Disruption-focused, no confirmed financial gain or direct public health impact yet
    • Technical context: SCADA networks with legacy software and limited cybersecurity in smaller utilities
      ๐Ÿ“Ž Coverage: worldwaterreserve.com ยท ๐Ÿ‘ via r/cybersecurity

๐Ÿ”“ CVEs & KEV

  • CVE-2026-55734 โ€” CVSS โ€” โ€” guardian atom exhaustion in Guardian.Permissions.encode_permissions!/1Allocat...
  • CVE-2026-55733 โ€” CVSS โ€” โ€” Atom-table exhaustion denial of service in Guardian permissions AtomEncoding ...
  • CVE-2026-54894 โ€” CVSS โ€” โ€” Atom-table exhaustion denial of service in Guardian via unbounded atom creati...
  • CVE-2026-55735 โ€” CVSS โ€” โ€” Guardian.revoke/3 acts on unverified token claims, allowing forged-token sess...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check