The whole point of an air-gapped hardware wallet is that it never touches the internet. Your keys stay offline, safe from hackers, malware, and all the digital gremlins that haunt crypto holders at night. Coldcard, one of the most trusted names in Bitcoin self-custody, built its reputation on exactly that promise.
That promise just took a serious hit. A firmware vulnerability present in Coldcard devices since March 2021 has been exploited to drain approximately 1,367 BTC, worth roughly $88.6 million to $89 million, from more than 4,500 wallets. The exploit didn’t require internet access to the device. It targeted the randomness used to generate recovery seeds, making them predictable enough for an attacker to reproduce offline.
How the exploit worked
The vulnerability existed in Coldcard firmware versions 4.0.0 through 5.0.3. A critical firmware change made in March 2021 inadvertently caused the device to default to a predictable software Random Number Generator for seed generation instead of utilizing the hardware-based True Random Number Generator, fundamentally undermining the wallet’s security premise. Security experts at Block investigated and revealed the predictable fallback behavior, enabling attackers to enumerate plausible seeds and access user funds without needing physical access to the devices or any network activity.
Galaxy Research tracked the activity across three distinct waves of attacks, suggesting a single sophisticated operator was behind the entire campaign. The method involved brute-forcing seed phrases offline, meaning the attacker didn’t need to compromise any network or device directly.
The initial wave hit on July 30, 2026. In roughly 25 minutes, approximately 594 BTC (around $38 million) was drained from about 500 addresses.
By August 2, total losses had climbed to approximately 1,367 BTC across at least 4,585 addresses. The compromised wallets shared a common trait: their recovery seeds were created without a BIP-39 passphrase. Wallets using multisignature setups remained unaffected.
The fallout for self-custody
Coinkite, the company behind Coldcard, has urged all affected users to generate new recovery seeds on updated firmware. Updating firmware does not retroactively fix seeds that were already generated with weak randomness. If your seed was created during the vulnerable period, it remains compromised regardless of what firmware you’re running now. You need a completely new seed on a patched device, and you need to move your funds to wallets derived from that new seed.
Reports indicate many Bitcoin holders are moving funds back to exchanges following the incident. Some analysts are speculating this could accelerate adoption of institutional custody alternatives, including Bitcoin ETFs.
What this means for investors
For current Coldcard users, the action items are straightforward but urgent. Anyone who generated a seed on firmware versions 4.0.0 through 5.0.3 should treat that seed as compromised, generate a new one on updated firmware with a BIP-39 passphrase, and transfer all funds immediately. Multisig users appear safe.
Watch for potential on-chain analysis identifying the attacker’s consolidation wallets. Galaxy Research’s identification of a single operator across three attack waves suggests law enforcement and blockchain forensics firms are already building a trail.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
16









English (US) ·