Coldcard wallet breach drains $130M in Bitcoin from 7,300 devices

2 hours ago 22
Coldcard wallet breach

A hardware wallet built to keep Bitcoin offline and out of reach of hackers has instead become the center of one of 2026’s costliest cryptocurrency thefts. The Coldcard wallet breach, tied to a firmware flaw quietly introduced back in March 2021, has drained more than $130 million in Bitcoin from thousands of supposedly secure devices, according to blockchain investigators tracking the fallout.

Key takeaways

  • A firmware defect from March 2021 weakened seed phrase randomness on Coldcard hardware wallets, cutting cryptographic key strength from 128 bits to just 40 bits.
  • At least 7,300 wallets have been drained across at least three documented attack waves, with total losses now topping $130 million in Bitcoin.
  • Blockchain analytics firm TRM Labs has traced the activity to at least 15 distinct threat actors, some likely opportunistic copycats.
  • Stolen funds have been routed through privacy tools including Wasabi and Tornado Cash, according to CertiK.
  • Coinkite, the maker of Coldcard, has urged affected users to update firmware and migrate to a brand-new seed phrase — though experts say a full hardware swap is safer.

Firmware Vulnerability at the Root of the Coldcard Wallet Breach

The problem traces back to a single line of code. A firmware build released in March 2021 routed seed phrase generation through a predictable software randomizer instead of the device’s dedicated hardware randomness chip, according to security researchers at Block who examined the flaw. That single defect left a limited, guessable pool of possible keys — something attackers with enough computing power could reproduce entirely offline, without ever touching a victim’s device.

The practical effect was devastating. What should have been a secure 128-bit cryptographic key was effectively reduced to just 40 bits of real entropy, according to the security assessments cited in coverage of the incident. That gap made brute-force cracking of affected wallets feasible for anyone who understood the flaw. Hackers weren’t breaking into a vault — they were learning how to cut a matching key from scratch.

Coinkite, the company behind Coldcard, published an advisory acknowledging the seed-generation weakness, updated over the following days, urging owners of affected devices to update their firmware and migrate funds to a freshly generated seed phrase.

Massive Theft Across Multiple Attack Waves

The Coldcard wallet breach did not happen all at once — it unfolded in escalating waves that grew more sophisticated as they went. Galaxy Digital’s research team confirmed at least three separate attack campaigns had drained cryptocurrency from 7,300 compromised wallets, with evidence pointing to a possible fourth wave still underway.

The scale of individual waves tells its own story. The opening wave, observed around July 30, swept roughly 1,083 Bitcoin from 1,196 addresses in just 41 minutes — nearly a full coin per victim. By the third wave, attackers were emptying wallets holding only a few thousand dollars each, draining about 208 Bitcoin from 1,912 addresses and spreading funds across separate destination addresses rather than a handful of shared collector wallets, making the money harder to trace.

An initial confirmed compromise on July 31 involving 594 Bitcoin, worth roughly $38 million at the time, helped trigger the wider alarm. Galaxy Research later verified cumulative losses had climbed past 1,596 Bitcoin, more than $100 million in value, before independent estimates from Galaxy Digital and crypto-monitoring firm Elliptic pushed the total above $130 million — a figure Elliptic co-founder Tom Robinson said was roughly accurate.

At Least 15 Threat Actors, With a Possible Fourth Wave Looming

Why does the number of attackers matter here? Because it shapes how quickly — or whether — the exploitation ends. TRM Labs’ analysis found variations in attack methodology across the different waves, pointing to the involvement of at least 15 independent threat actors rather than a single coordinated group. Most of the stolen cryptocurrency remains consolidated in a limited number of attacker-controlled addresses, TRM Labs noted, even as tactics shift wave to wave.

CertiK analysts believe some of the smaller, more recent transactions may not even come from the original attackers. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK representative said. Dragonfly managing partner Haseeb Qureshi added a striking detail: certain AI models identified the underlying weakness in under 20 minutes, and he estimated that roughly two dollars worth of AI-assisted security testing could have flagged — and possibly prevented — the entire breach before it happened.

The Coldcard wallet breach now ranks as the third-largest cryptocurrency theft recorded in 2026, a year that has already seen more than 200 separate hacks targeting crypto companies and a combined loss north of $950 million, according to TRM Labs.

Stolen Funds Funneled Into Privacy Protocols

Once the coins moved, the next question became where they went. CertiK’s tracking of the compromised assets found a Bitcoin privacy-enhancing protocol called Wasabi received roughly 64 Bitcoin, which was worth $4.17 million at the time, while roughly 200 Ether worth about $380,000 was funneled through Tornado Cash, the Ethereum mixing service long associated with laundering stolen crypto.

These privacy tools don’t erase a transaction from the blockchain, but they do make it considerably harder for investigators to follow the money to a final cash-out point. The use of both Bitcoin- and Ethereum-based mixing services suggests attackers were diversifying their laundering methods across multiple chains rather than relying on a single obfuscation path.

Bitcoin Network’s Response and What Affected Users Should Do

The breach didn’t just move money — it moved the entire network. Blockchain intelligence provider Glassnode recorded a surge in Bitcoin active addresses, climbing to approximately 980,000 daily transactions in the days following the exploit, the highest level of on-chain activity since December 2024.

Glassnode was careful to frame that spike correctly: it wasn’t bullish trading. “An operational security response, not a change in market conviction,” is how the analytics firm characterized the jump. Previously dormant Bitcoin holdings — valued at nearly 200 times the size of the original theft — suddenly became active, a clear sign that holders across the network were rushing to move funds to safer storage rather than reacting to price momentum.

What Coldcard Owners Should Do Now

Security professionals are blunt about the limits of a firmware patch alone. Cybersecurity experts warn that simply updating firmware provides insufficient protection for anyone who already initialized a wallet on an affected device. Their advice: generate a brand-new wallet on secure hardware and transfer all assets immediately, rather than trusting an update to retroactively fix a seed phrase that may already be compromised.

That warning carries weight in light of accounts like Jonathan Goodman’s. He said he lost $1.6 million from his Coldcard wallet despite following every recommended precaution. “Perhaps the hardest part about this is that I did everything right,” Goodman wrote, describing how he never shared his seed phrase, never connected his devices to the internet, and stored everything across multiple safes and safety deposit boxes. “None of it mattered,” he said, “all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.”

That’s the uncomfortable lesson of the Coldcard wallet breach: even flawless personal security practices can’t compensate for a defect buried inside the hardware itself, years before anyone notices it.

FAQ

What caused the Coldcard hardware wallet breach?

A firmware vulnerability introduced in March 2021 reduced the randomness in seed phrase generation, weakening cryptographic key strength from 128 to 40 bits and enabling brute-force attacks against affected wallets.

How many Coldcard wallets were compromised in the breach?

At least 7,300 wallets have been compromised across at least three documented attack waves, with signs pointing to a possible fourth wave still in progress.

What was the total value of Bitcoin stolen in the Coldcard breach?

Total theft exceeds $130 million in Bitcoin, making this the third-largest crypto theft recorded in 2026.

What should Coldcard users do if their wallet was affected?

Security experts advise fully replacing the compromised device with new hardware and generating a brand-new seed phrase, then transferring all assets, since a firmware update alone does not guarantee protection for wallets initialized before the fix.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

Read Entire Article