TLDR
A long running firmware flaw in Coldcard hardware wallets has been exploited to steal around 130 million dollars worth of Bitcoin, putting thousands of self custodial users at risk.
- Attackers guessed weak wallet seeds created since 2021, draining at least 1,596 BTC and possibly up to roughly 2,055 BTC from about 7,300 Coldcard addresses.
- The incident is pushing many holders to move Bitcoin, driving 2026 highs in onchain activity and renewed interest in institutional custody through spot Bitcoin ETFs.
- Most stolen coins remain unmoved, while patched firmware, migration guidance, and law enforcement monitoring will shape how much damage ultimately crystallizes.
Confidence: high that losses exceed one hundred million dollars, moderate that total damages settle near one hundred thirty million dollars as suspected cases are confirmed.
Deep Dive
1. How The Coldcard Exploit Worked
Coldcard devices from Coinkite used a firmware path that accidentally replaced their hardware random number generator with a much weaker software fallback when creating wallet seeds. That bug reduced effective entropy from an intended 128 bits to roughly 40 bits on older models and about 72 bits on newer ones, making some private keys realistically guessable rather than astronomically hard to brute force, as detailed in this technical explainer.
Galaxy Research and other analysts report at least 1,596 BTC stolen across three confirmed attack waves and several smaller incidents, with potential losses up to about 2,055 BTC, or roughly 130 million dollars at current prices, when suspected cases are included. Only wallets whose seeds were generated on vulnerable firmware are affected; the Bitcoin network itself was not compromised.
Coinkite has released fixed firmware and urged users to generate new seeds and move funds, stressing that simply updating firmware does not protect wallets created with weak seeds. Those original seeds remain guessable until funds are transferred to addresses created with secure randomness.
2. Impact On Bitcoin Activity And Custody Debate
The exploit triggered a rush of Bitcoin movements as users tried to escape any potential exposure. Research firms report seven day active supply near year highs and hundreds of thousands of BTC moved on chain, with whale transactions and active addresses spiking, as described in this onchain activity analysis.
Despite the thefts, Bitcoin has held around the mid sixty thousand dollar area, with volatility surprisingly muted compared with prior stress events. Analysts note that such surges in active supply often appear near local tops or bottoms, but on their own do not guarantee a directional move.
At the same time, spot Bitcoin ETFs in the United States have seen strong net inflows while the Coldcard story unfolded, reinforcing the argument that institutional grade custody is a feature rather than a drawback for many investors, according to ETF flow reports.
Self custody is powerful but not automatically safer; hardware and firmware risks can be systemic, so many users are re evaluating mixes of hardware wallets, multisig, and institutional custody.
3. What To Watch Next
Galaxy Research estimates that about ninety percent of the stolen BTC has not yet moved, and compromised addresses have been shared with exchanges and law enforcement, making those coins among the most closely monitored in Bitcoin history, as highlighted in this losses and monitoring summary. Monetizing them at full value will be difficult because regulated venues can refuse deposits linked to the hack.
On the remediation side, Coinkites guidance and community initiatives such as Muneeb Alis proposed victim reimbursement fund will influence how much harm is ultimately absorbed by individual users versus broader markets, as described in a fund proposal overview. There is also a wave of phishing and fake migration schemes targeting worried users, so verification of any instructions against official channels is critical.
Regulators and security experts are using the case to argue for stricter independent audits of wallet firmware and better randomness testing, which could improve hardware wallet quality across the industry over time.
Conclusion
Coldcards flaw has turned into one of the largest self custody failures seen in Bitcoin, with confirmed losses over one hundred million dollars and a likely ceiling near one hundred thirty million dollars as investigations finish. The Bitcoin protocol remains intact, but the incident is reshaping views on custody, driving heavy onchain repositioning and strengthening the appeal of institutional solutions while highlighting that secure randomness and audited firmware are just as important to safety as keeping keys offline.
