TLDR
A flaw in Coldcard Bitcoin hardware wallets has enabled attackers to steal roughly $130 million in BTC, with losses still being refined by investigators.
- The incident stems from weak recovery seed generation in certain Coldcard firmware, allowing private keys to be reconstructed remotely.
- Confirmed thefts are in the low hundreds of millions of dollars in BTC, and the exploit has triggered record on-chain activity and a renewed custody debate.
- Users and institutions are reassessing hardware wallet practices, with more scrutiny on firmware, seed handling, and regulated custody options such as spot Bitcoin ETFs.
Deep Dive
1. What Happened Technically
Security research shows that some Coldcard devices generated wallet recovery seeds using a deterministic software random number generator instead of a true hardware random source, drastically reducing entropy and making some private keys guessable.
Galaxy Research and others have traced at least 1,596 BTC stolen from about 7,300 addresses, with a possible fourth wave lifting losses toward 2,055 BTC, roughly $130 million, though part of that figure remains unconfirmed pending victim reports. Investigations also note that about 90 percent of stolen BTC has not moved since the attacks, giving exchanges and law enforcement time to track the funds in heavily watched UTXOs.
A wallet can be air-gapped and still fail if its seed generation is flawed, because the attacker only needs to reconstruct the seed, not access the device.
2. Scale Of Losses And Market Impact
Several analyses put confirmed Coldcard thefts in the $110 million to $120 million range, while broader estimates, including suspected but not yet fully verified addresses, reach about $130 million in BTC, a scale that makes this one of the largest self-custody failures on record.
Despite the shock, Bitcoin has held around the mid-$60,000s, but on-chain metrics show seven-day active supply and whale transaction counts at 2026 highs as affected users move coins off vulnerable wallets and into exchanges or new setups. ETF flow trackers report notable net inflows into US spot Bitcoin ETFs around the same time, as some investors appear to favor institutional custody over managing hardware wallets themselves.
3. Custody Debate And What To Watch
Analysts highlight a tradeoff: self-custody avoids third-party risk but depends entirely on correct wallet design, firmware, and seed handling, while regulated custody shifts these risks to professional providers at the cost of trust and regulation exposure.
In response, Coldcards manufacturer has pushed emergency firmware updates and migration guidance, and rival wallet makers are reminding users that importing a compromised seed into another device does not fix the problem; only generating a new, secure recovery phrase and moving funds to fresh addresses can do that. Over the next weeks, expect more security audits, firmware changes, phishing attempts that exploit user fear, and continued discussion about multisignature setups and ETF-based exposure.
For anyone using hardware wallets, the key is not just offline storage but verifiable randomness, up-to-date firmware, and careful migration plans if a device or seed type is ever flagged as weak.
Conclusion
The Coldcard incident shows that Bitcoins main vulnerability often lies not in the protocol, but in the tools people use to hold it. A single design flaw in seed generation has produced nine-figure losses, reshaped on-chain behavior, and pushed some capital toward regulated custody. Watching how wallet providers harden their designs and how flows shift between self-custody, exchanges, and ETFs will be crucial for understanding both security and market structure in the months ahead.
