Bitcoin investors using one of the most trusted hardware wallets on the market have lost over $100 million in a sophisticated exploit that went undetected for more than five years. The attack, first detected on July 30, 2026, targeted Coldcard hardware wallets manufactured by Canadian company Coinkite. According to blockchain research firm Galaxy Research, at least 1,596 bitcoins—worth approximately €88 million at the time of reporting, with estimates rising to €111 million—have been drained from over 7,000 wallet addresses.
What Happened? A Vulnerability Hidden Since 2021
The root of the problem lay in a firmware bug introduced in March 2021. Coldcard devices are designed to be the Fort Knox of Bitcoin storage: small, calculator-like machines that generate a secret recovery phrase (seed) used to secure crypto holdings. However, a misplaced preprocessor directive caused the firmware to silently fall back on a weak software-based random number generator instead of the device's dedicated hardware true random number generator (TRNG). The result was that seeds were generated with drastically reduced entropy—as little as 40 bits on older models, compared to the expected 128 bits—making them practical to brute-force.
Security researchers at Block (formerly Square) detailed how the flawed code allowed attackers to precompute candidate seed databases and then systematically sweep deposits in real time without ever touching the devices. "The vulnerability meant that an attacker who never had physical access to the Coldcard could still derive the private keys and steal the funds," Galaxy's research team noted.
How the Attack Unfolded
The theft occurred in multiple waves. The initial attack, which lasted just 41 minutes, saw roughly $70 million in bitcoin drained from approximately 1,200 addresses. Additional waves followed, including a 25-minute sweep of about 500 wallets netting another $38 million. Galaxy Research has tracked at least 15 independent attackers exploiting the same flaw. The perpetrator behind the largest sweep remains unidentified.
Coinkite disclosed the vulnerability on July 30, 2026, and released emergency firmware updates the following day. However, the company stressed that updating firmware does not fix already-generated seeds—affected users must generate entirely new seeds on patched firmware and move their funds immediately. In a public statement, Coinkite warned: "Customers still face risk that their crypto will be stolen. Move your bitcoins to a safe location now."
The incident has shaken confidence in the hardware wallet market. For years, the mantra "not your keys, not your coins" drove users toward self-custody hardware wallet solutions like Coldcard. Now, that trust is being questioned.
Broader Implications for Crypto Security
The Coldcard exploit comes amid a turbulent year for cryptocurrency security. In February 2025, the Bybit exchange suffered a $1.5 billion hack attributed to North Korean state-sponsored hackers. A separate incident saw $100 million stolen from celebrity crypto accounts. These events, combined with the latest hardware wallet breach, have reignited debate over whether centralized exchange custody might occasionally be safer than self-custody.
Industry figures have weighed in. Changpeng "CZ" Zhao, former CEO of Binance, commented on the irony that a device marketed as the most secure option could harbor such a deep-rooted flaw. Meanwhile, bitcoin security best practices are being reexamined, with experts now emphasizing the importance of adding extra entropy through dice rolls or strong BIP-39 passphrases.
FAQ
What caused the Coldcard wallet hack?
A firmware bug introduced in March 2021 caused Coldcard devices to generate recovery seeds using a weak software random number generator instead of the secure hardware TRNG. This made seeds predictable and allowed attackers to brute-force private keys.
How much bitcoin was stolen in the Coldcard exploit?
As of August 12, 2026, Galaxy Research had "high confidence" that at least 1,596 BTC (over €88 million) was stolen from roughly 7,300 addresses. Total losses could reach €111 million.
Are Coldcard wallets still safe to use?
Updated firmware (released July 31, 2026) fixes the flaw for future seed generation. However, any seed created on affected firmware (March 2021–July 2026) is potentially compromised. Users must generate new seeds on patched devices and transfer all funds.
Who is behind the Coldcard hack?
The attackers remain unknown. Galaxy Research identified at least 15 independent actors exploiting the same vulnerability, suggesting the flaw became widely known in criminal circles after the initial wave.
Does this affect other hardware wallets?
No. The vulnerability is specific to Coldcard firmware versions with the flawed preprocessor check. Wallets from Ledger, Trezor, and other manufacturers are not affected.
Follow Discussion