Need help? Support
BITCOIN
Tether Dominance USDT.D

Coldcard exploit drives BTC losses above $100M

Published 554 words 3 min read

TLDR

A vulnerability in Coldcard Bitcoin hardware wallets has been exploited in multiple waves, with research now estimating losses above $100 million in BTC.

  1. Galaxy Research and others link four attack waves draining roughly 1,800 BTC, with upper estimates around $118 million at recent prices.
  2. The flaw is in Coldcards seed generation firmware, which produced weak, guessable private keys, while the Bitcoin protocol itself remains uncompromised.
  3. The incident is pushing many holders from self-custody back to exchanges and may reshape hardware wallet security standards and legal liability for wallet makers.

Deep Dive

1. Scale Of The Losses

Initial reports described a single 25 minute sweep that drained about 594 BTC, roughly $38 million, from around 500 Coldcard wallets in late July 2026. Subsequent on-chain analysis tied additional waves of theft to the same weakness, with figures climbing past 1,083 BTC, then 1,367 BTC, and now an estimated 1,816 BTC stolen across more than 5,000 addresses, valued near $118 million at current prices according to four coordinated attack waves.

Numbers differ slightly between firms because some track only confirmed sweeps while others include suspected victim addresses still at risk, but all credible estimates place total losses well above $70 million, with the upper bound comfortably over $100 million.

2. Technical Cause And Responsibility

The exploit targets a bug in Coldcards firmware seed generation, not Bitcoin itself. A build error introduced around March 2021 caused affected devices to use a predictable software random number generator instead of their hardware RNG, slashing entropy from 128 bits to roughly 40 bits on Mk3 units and about 72 bits on later models, as detailed in a seed generation bug analysis.

That made many seeds mathematically guessable, allowing attackers to precompute vulnerable keys, then sweep wallets without touching the devices. Coinkite has acknowledged the flaw, issued firmware fixes, and advised users that merely updating does not secure previously generated seeds, a point reinforced in the Coldcard exploit explained.

Importantly, security commentators stress that the Bitcoin network was not hacked; this is a third party hardware failure in key generation, as clarified in Bitcoin was not hacked.

3. Impact On Users And What To Watch

On-chain data shows a sharp behavioral shift. After years of exchange outflows driven by events like FTX, the Coldcard crisis is instead pushing coins back to centralized venues, with net inflows and small holder deposits to exchanges spiking since July 31, as highlighted by net transfer of bitcoin from self-custody wallets to exchange addresses.

Coldcard owners with seeds generated on vulnerable firmware and without extra entropy or passphrases are the highest risk group, while multisig setups and dice based seeds appear far more resilient. Victims are already exploring collective legal action against Coinkite over losses exceeding 1,300 BTC, a potential class action threat that could set precedents for hardware wallet liability.

What this means

The main risk is in how keys were created, not in Bitcoin itself, so future trust will depend on transparent randomness, multisig adoption, and diversified custody rather than abandoning self-custody entirely.

Conclusion

The Coldcard exploit is one of the largest hardware wallet failures seen in Bitcoin, with losses now plausibly exceeding $100 million. It exposes how a single entropy bug in seed generation can undo years of safe cold storage and is already pushing users toward exchanges and more conservative custody options.

For crypto users, the lesson is that self-custody security depends on the entire key generation chain and that robust randomness, redundancy, and ongoing verification matter as much as keeping coins offline.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top