Hackers exploit Coldcard firmware flaw, stealing $89 million in Bitcoin from thousands of wallets

1 hour ago 13

The whole point of a cold wallet is that it’s cold. Offline. Air-gapped. Unreachable. A vulnerability in Coldcard hardware wallets just proved that premise has an asterisk.

Hackers exploited a firmware flaw in Coldcard devices produced by Canadian manufacturer Coinkite, draining approximately 1,367 BTC, valued at nearly $89 million, from 4,585 addresses across several waves of attacks beginning July 30, 2026.

What actually happened

The vulnerability traces back to a March 2021 firmware build affecting Coldcard Mk3 versions 4.0.1 through 4.1.9 and earlier releases.

The flaw was in how those devices generated wallet seeds. Instead of routing entropy through the hardware random number generator, a bug pushed the process through a software RNG. In English: the randomness used to create your private key was far less random than advertised, making it mathematically feasible to reconstruct keys offline without ever touching the physical device.

The first wave hit on July 30, 2026. Roughly 594 BTC, around $38 million at the time, was drained from approximately 500 dormant addresses in under 30 minutes. That’s not a slow, probing attack. That’s a coordinated sweep.

Subsequent waves pushed total losses to 1,367 BTC across 4,585 addresses by early August 2026. Galaxy Research tracked the incident and noted the attacker’s tactics evolved with each wave, specifically to evade tracing while picking off smaller balances. Galaxy Research also assessed that each wave was likely conducted by a single operator.

The dormant address pattern matters here. Wallets that hadn’t moved funds in years were being emptied, suggesting the attacker had pre-computed a large set of vulnerable keys and was executing a systematic drain rather than reacting to live activity.

Coinkite’s response and who’s affected

Coinkite issued a security advisory and released patched firmware by August 1, 2026, roughly two days after the first wave began.

The company advised users whose seeds were generated on affected firmware versions to migrate funds to new seeds immediately, unless they had supplemented the wallet’s entropy with an independent source or used a strong BIP-39 passphrase. BIP-39 passphrases act as a 25th word on top of the standard 24-word seed phrase, and a robust one would have made offline key reconstruction significantly harder even with the reduced entropy flaw.

Coinkite confirmed that several other products in its lineup, including TAPSIGNER, OPENDIME, and SATSCARD, were not affected by the exploit. The blast radius was specific to the firmware versions in question.

What this means for self-custody

This incident complicates the self-custody narrative without fully dismantling it. What the Coldcard exploit demonstrates is that hardware wallets carry their own category of risk, specifically firmware integrity and supply-chain trust, that can be just as catastrophic.

Reports following the attack indicate some users have begun moving Bitcoin back to centralized exchanges, treating them as safer in the short term.

For investors holding Bitcoin in cold storage, the immediate questions are practical: which firmware version was used to generate the seed, whether an independent entropy source or BIP-39 passphrase was applied, and whether migration to a new seed on patched firmware has happened yet. Devices running unaffected firmware or supplemented with strong passphrases were not in the attacker’s target set.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article