TLDR
A firmware flaw in Coldcard Bitcoin hardware wallets has been exploited to drain around $89 million of BTC from thousands of self custody users.
- Attackers abused a weak random number generator in Coldcard firmware dating back to 2021, with Galaxy Research confirming at least 1,367 BTC stolen across about 4,585 addresses in multiple waves.
- The exploit made wallet seeds guessable but did not hack the Bitcoin protocol, yet it triggered a spike in BTC moves back to exchanges and added short term selling pressure.
- Coinkite has patched firmware, halted shipments and destroyed affected units, while researchers warn a fourth attack wave is possible and call for independent audits of hardware wallet security.
Deep Dive
1. Firmware Bug And Losses
Reports from Galaxy Research and others say a bug in Coldcards seed generation routed wallet creation to a weak software pseudo random number generator instead of the intended hardware source, cutting entropy far below best practice for private keys. As a result, attackers could regenerate seeds from public data and systematically sweep funds without touching devices, leading to confirmed losses of about 1,367 BTC, roughly $88.6 million, across 4,585 addresses as of early August 2026 according to on chain analysis in the Coldcard PRNG vulnerability write up. Some later estimates that include suspected addresses put potential losses nearer 1,800 BTC and around $118 million, showing both confirmed and ongoing risk.
2. Bitcoin And Self Custody Impact
Security analysts stress that Bitcoin itself was not compromised; the failure is in a specific hardware wallets key generation, not the underlying protocol, as clarified in a detailed Bitcoin protocol explainer. Even so, the incident shook confidence in self custody. CryptoQuant data cited by Crypto.news shows small holders moved 39,600 BTC in sub 1 BTC transfers in a single day and net flows shifted back toward exchanges, while market coverage noted BTC briefly slipping below 63,000 dollars as fear around cold storage grew.
Hardware wallets still reduce many risks, but seed generation and vendor firmware become critical points to monitor, and relying on a single device or implementation concentrates security risk.
3. Industry Response And What To Watch
Coinkite has shipped patched firmware for Coldcard models, halted new shipments and destroyed remaining affected units, and is cooperating with investigators, according to multiple postmortems and security notices referenced in Galaxy Research coverage. Security leaders, including Krakens chief security officer, are using the event to argue for independent, standards based testing of wallet randomness, as outlined in a call for audits following the Coldcard exploit. Analysts also warn the exploit may continue until all vulnerable seeds are migrated, with a fourth coordinated attack wave already observed in on chain data.
Conclusion
The Coldcard incident is one of the largest hardware wallet failures in Bitcoin history, driven by a long lived firmware randomness bug rather than a flaw in Bitcoin itself. For crypto users, the key lessons are that secure key generation and diversified custody assumptions matter as much as being offline, and that future waves and industry audit efforts will be important signals for how self custody practices evolve from here.
