Need help? Support
BITCOIN
Tether Dominance USDT.D

Coldcard exploit steals $70M from hardware wallets

Published 629 words 3 min read

TLDR

A critical flaw in Coldcard Bitcoin hardware wallets let attackers reconstruct seeds offline and drain roughly $70 million, shaking confidence in self-custody devices.

  1. An old firmware bug reduced seed randomness, letting an attacker sweep about 1,082 BTC from nearly 1,200 Coldcard wallets in under an hour.
  2. Risk is concentrated in seeds generated on specific Coldcard firmware, while wallets with extra entropy or strong passphrases and other hardware brands appear largely unaffected.
  3. The incident shows hardware wallets rely on robust key generation and that diversifying setups and watching vendor security advisories is now more important for crypto users.

Deep Dive

1. Exploit And Scale

Investigations from Galaxy Research and others indicate more than 1,000 BTC, valued around $70 million, were drained from about 1,196 Coldcard wallets in a 41 minute window on 30 Jul 2026, without any devices being physically touched, as detailed in a Coindesk analysis.

A firmware bug dating back to March 2021 caused certain Coldcard models to fall back to a predictable software random number generator seeded by chip serial numbers and clock readings, shrinking effective seed entropy from 128 bits to roughly 4072 bits. That made seeds computationally enumerable, so the attacker could generate candidate seeds, derive addresses, check balances on the Bitcoin blockchain, and automatically sweep funds.

Initial reports spoke of about 594 BTC stolen from around 500 wallets, but expanded analysis linked over 1,082 BTC and nearly 1,200 addresses, with some newer data suggesting totals may still shift slightly as more movements are traced.

2. Who Is At Risk

The vulnerability affects recovery seeds created on specific Coldcard firmware versions, notably Mk3 devices and some Mk4, Mk5 and Q units running releases from 4.0.1 onward, where the faulty randomness was present, according to Bitcoin.coms incident explainer. Long dormant self-custody wallets were disproportionately hit.

Coldcard maker Coinkite has acknowledged the bug, apologized and shipped emergency firmware updates, but they stress that simply updating firmware does not repair a seed generated under the flawed code; users need a new seed on fixed firmware and a careful migration path. Wallets whose owners added significant dice roll entropy or strong BIP 39 passphrases appear to have resisted the attack, because those additions pushed effective randomness back into a harder to brute force range.

Competing hardware wallet vendors such as Ledger and Trezor have publicly stated they are not affected and have highlighted their own randomness sources, as summarized in a Crypto.news Q&A.

What this means

If you ever generated a seed on Coldcard during the affected period, the key question is how it was created and whether it followed Coldcards latest security guidance.

3. Self-Custody And Market Impact

This exploit directly attacks one of the core narratives of Bitcoin self-custody that an offline hardware wallet is the safest option. Sentiment data shows fear around self-custody hitting record levels relative to past crises, according to Santiment referenced by CryptoPotato.

Bitcoins price reaction so far has been modest compared with the psychological impact. Much of the broader move is being attributed to macro factors, yet the Coldcard case is driving a renewed debate about diversification across wallet types, more rigorous code audits and entropy testing for hardware makers, and whether regulators should treat consumer hardware wallets more like financial products with explicit oversight.

Binance founder Changpeng Zhao has used the event to warn that even hardware wallets can have bugs and to encourage spreading funds across multiple setups, as covered in Coindesks coverage of his comments.

Conclusion

The Coldcard exploit did not hack devices directly, but rather exploited a subtle randomness bug that made seeds guessable and turned thousands of cold wallets into low hanging fruit.

For crypto users, the key lesson is that offline storage is only as strong as its key generation process and ongoing vendor security practices, and that reviewing how your own keys were created and how your wallets are diversified is now a crucial part of risk management.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top