Need help? Support
BITCOIN
Tether Dominance USDT.D

Coldcard wallet exploit steals over $150M BTC

Published 572 words 3 min read

TLDR

A Coldcard hardware wallet vulnerability has enabled attackers to steal more than 2,400 BTC, potentially over $150 million in Bitcoin, from self-custody users.

  1. Galaxy Researchs onchain analysis attributes at least 1,778 BTC (~$112 million) in confirmed Coldcard-related thefts, with a suspected fourth wave pushing losses toward 2,417 BTC (~$151 million).
  2. The exploit stems from a 2021 firmware bug that weakened seed randomness, letting attackers reconstruct wallet seeds from device data, affecting single-signature Coldcard users who generated seeds on vulnerable versions.
  3. The incident is a major wake-up call for Bitcoin self-custody, pushing users toward patched hardware, multi-signature setups, and even ETF-style custody, while researchers warn the final loss figure could still rise.

Deep Dive

1. Scale And Timeline

Galaxy Researchs onchain tracking shows the Coldcard exploit has already stolen over 1,778 BTC from more than 5,200 addresses, with three major waves of theft and dozens of smaller incidents, beginning on 30 July 2026. A possible fourth wave of 638.5 BTC would lift total thefts to about 2,417 BTC, or roughly $151.3 million at recent prices, according to a detailed Galaxy Research report.

Wave 1 alone saw 1,082.65 BTC taken from 1,195 addresses, with other clusters losing over 200 BTC each. As of mid August, around 1,499 BTC remained unspent in attacker-controlled wallets, with some funds routed through coinjoin privacy tools and small amounts reaching exchanges such as KuCoin and trading firms like Jump Crypto.

Galaxy has spoken directly with more than 190 victims and considers its figures high confidence, although it warns the total may still increase as additional thefts are confirmed.

2. How The Exploit Worked

The root cause is a 2021 Coldcard firmware change that quietly shifted seed generation from a dedicated hardware random-number chip to a weaker software method, cutting entropy from 128 bits to as low as 40. With fewer possible seed combinations, attackers could reconstruct seeds using information such as device serial numbers and clock states, without phishing, malware, or physical access.

This primarily affects single-signature Coldcard wallets whose seeds were generated on the flawed firmware between 2021 and the fix. Coinkite has patched the bug in newer releases but cannot retroactively repair seeds that were already created, so vulnerable users must move funds to fresh, secure wallets to eliminate risk.

What this means

If a wallets seed was created on affected Coldcard firmware, the main protection is gone; security now depends on whether attackers have already reconstructed and swept that seed.

3. Implications For Bitcoin Users

The exploit highlights that hardware wallets are not risk free; a single firmware mistake can compromise thousands of offline wallets. The scale of losses has renewed debate around self-custody versus third-party solutions like spot Bitcoin ETFs, with some analysts noting strong ETF inflows following a Coldcard exploit coverage that framed the incident as a self-custody wake-up call.

For Bitcoin users, the practical takeaway is to treat wallet firmware and seed-generation methods as critical security surfaces, favor multi-signature setups where possible, and monitor vendor advisories closely. Researchers also warn that AI-assisted analysis of code and onchain data can make similar vulnerabilities easier to discover and exploit in the future.

Conclusion

The Coldcard exploit shows that even respected hardware wallets can fail at the most fundamental layer, seed generation, and that such failures can translate directly into nine-figure Bitcoin losses. For crypto users, the path forward is not abandoning self-custody but upgrading practices: verifying firmware, regenerating seeds on secure setups, and using more robust schemes like multi-signature or institutional-grade custody where appropriate. The key thing to watch now is whether any further theft waves emerge and how quickly the wider ecosystem tightens security in response.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top