TLDR
A critical Coldcard hardware wallet bug let an attacker reconstruct private keys and drain a large batch of Bitcoin, with early losses estimated around 38 million dollars and later totals nearer 70 million dollars.
- The exploit hit seeds generated on vulnerable Coldcard firmware since 2021, initially draining about 594 BTC from roughly 500 wallets in minutes before analysis raised losses toward 1,083 BTC.
- The flaw sharply reduced seed randomness, making some Coldcard recovery phrases guessable offline and exposing long term holders despite devices never being physically touched.
- Coldcard has shipped fixed firmware and urged users with affected seeds to create new wallets and move funds, while the incident is pushing debate toward custodians and spot Bitcoin ETFs.
Deep Dive
1. Exploit Scale And Timeline
Reports first highlighted a coordinated sweep where about 594 BTC, worth roughly 38 million dollars, were drained from around 500 Coldcard wallets in a 25 minute window on 30 July 2026. Later forensic work by Galaxy Research and others linked up to 1,196 addresses and roughly 1,082 to 1,128 BTC, valued near 70 to 71 million dollars, to the same exploit over about 41 minutes, making this one of the largest self custody failures in Bitcoin history.
Chainalysis found the attacker prioritized high value wallets, stealing around 30 million dollars in the first 10 minutes and then moving on to smaller balances, indicating careful pre analysis of the victim set. The stolen coins were rapidly consolidated and have mostly remained parked in a few addresses since the sweep.
2. Technical Flaw And Self Custody Risk
The root cause was a firmware bug introduced around March 2021 that changed how Coldcard devices generated seed phrases. Instead of relying fully on a hardware random number generator, vulnerable versions fell back to a weaker MicroPython software process that used predictable device data like serial numbers and clock readings.
On Mk3 devices, this reduced effective entropy to about 40 bits, and some newer models to around 72 bits, far below the intended 128 bits, which made brute force reconstruction of seeds feasible with specialized tooling. Users who added at least 50 independent dice rolls or used strong BIP 39 passphrases, as Coldcard allows, were largely protected, and multisig setups using Coldcard plus other signers were also much safer.
Bitcoins underlying cryptography was not broken; the weak link was seed generation in one wallet line, showing that self custody risk is largely implementation and operational, not protocol level.
3. User Actions And Market Impact
Coldcard maker Coinkite has acknowledged responsibility, released emergency firmware updates and advised that simply updating firmware does not secure seeds created under the flawed versions. Their guidance is that affected users need to generate entirely new seeds on patched firmware and carefully migrate funds, treating old seeds as compromised even if balances were not drained.
Industry voices, including Binance founder CZ, have used the incident to argue for spreading holdings across multiple wallets and considering layered setups such as multisig and regulated custodians for larger balances. Commentators also note that such high profile hardware failures may accelerate interest in institutional custody and spot Bitcoin ETFs as some users reassess the tradeoff between trust and operational complexity.
Conclusion
The Coldcard exploit shows that even respected hardware wallets can harbor long lived flaws that only surface when attackers find them, turning a single bug into tens of millions of dollars in Bitcoin losses. For crypto users, the practical lesson is that no single device or brand is absolute protection; robust security comes from diversity of tools, independent entropy, and layered custody rather than relying on one wallet as the sole line of defense.
