TLDR
A critical bug in Coldcard Bitcoin hardware wallets allowed an attacker to recreate private keys offline and steal about 70 million dollars from supposedly safe cold storage.
- Around 1,082 BTC, worth roughly 70 million dollars, were drained from about 1,196 Coldcard wallets in a 41 minute automated sweep on 30 July 2026.
- The exploit came from a firmware bug that produced weak, guessable seed phrases on certain devices, while users who added extra dice entropy or strong passphrases mostly avoided losses.
- The incident undermines confidence in self custody and shows hardware wallets still carry software risk, making seed generation quality and diversification key things to watch.
Deep Dive
1. Scale And Pattern Of The Theft
Galaxy Research and multiple analyses report that about 1,082.65 BTC were swept from roughly 1,196 Coldcard wallets over six blocks between 01:10 and 01:51 UTC, all in one coordinated burst, with losses near 70 million dollars at the time of the attack. CoinDesks report notes identical fee settings and no change outputs, indicating automated batch sweeps rather than manual transactions.
Later work from Galaxy, summarized by Cointelegraph, expanded initial estimates of 594 BTC lost to more than 1,000 BTC, mostly from wallets holding between 1 and 50 BTC that had been dormant for years.
This was not a slow drip or isolated hack but a one shot drain of many long term self custody users, which is structurally different from an exchange breach.
2. How A Cold Wallet Was Exploited
The attack did not touch devices directly. A firmware bug introduced in March 2021 caused some Coldcard models to skip their hardware randomness and instead use predictable chip data and clock values to generate seed phrases, massively reducing entropy. Analysis from Galaxy and Coinkite, explained in Bitcoin.coms technical breakdown, shows effective randomness fell to about 40 bits on some Mk3 devices, making brute force enumeration feasible.
Attackers generated billions of possible seeds offline, derived addresses, and checked them against the public Bitcoin blockchain, then automatically swept any wallets with balances. Users who rolled physical dice for extra entropy or used strong BIP39 passphrases were largely spared, because those additions made their seeds impossible to reconstruct.
Coinkite has acknowledged the bug, shipped emergency firmware updates, and stressed that updating firmware alone does not fix an already vulnerable seed. Funds must be moved to new wallets created on fixed firmware.
3. Impact On Self Custody And What To Watch
Sentiment data and coverage such as Galaxy Digitals overview show fear around Bitcoin self custody spiking to record levels, since a respected hardware wallet failed at the core task of generating secure keys. Binance founder CZ publicly urged users to spread funds across multiple wallets after the exploit, as reported by CoinDesk, while warning that diversification introduces its own operational risks.
Key things to watch now are: further sweeps of Coldcard generated addresses, how quickly users migrate off vulnerable seeds, whether hardware wallet makers improve entropy testing and audits, and whether regulators or large custodians use this incident to argue for more centralized solutions.
For crypto users, the edge is in understanding that offline is not enough; you want truly random seeds, layered defenses like passphrases or multisig, and an eye on vendor security practices.
Conclusion
The Coldcard exploit shows that a single subtle software flaw can turn highly trusted cold storage into a large attack surface, with tens of millions of dollars lost in minutes. For the broader Bitcoin (BTC) ecosystem, it is a reminder that self custody delivers control but also concentrates technical risk, so future resilience will hinge on better randomness, independent audits, and thoughtful diversification rather than blind trust in any one wallet brand.
