TLDR
A Coldcard hardware wallet firmware bug has enabled remote theft of Bitcoin, with Galaxy Research estimating about $115 million in BTC losses so far.
- Roughly 1,778 BTC have been swept from about 8,680 Coldcard based addresses in multiple coordinated attack waves since late July 2026.
- The root cause is a flawed seed generation process that weakened randomness, letting attackers reconstruct private keys without ever touching the hardware wallets.
- Parallel data breaches and malware campaigns against other wallet providers are increasing phishing and even physical attack risks for self custody users.
Deep Dive
1. Scale Of The Coldcard Losses
Galaxy Research reports that Coldcard related thefts now exceed $115 million, with around 1,778.58 BTC drained from 8,680 addresses since July 30, based on BTC prices at the time each theft occurred. This includes an initial Wave 1 sweep where attackers stole 1,082.65 BTC from 1,195 wallets in about 41 minutes, worth about $70.2 million at the time, across several Bitcoin blocks in tightly batched transactions. Most of these funds remain unmoved in collector wallets, suggesting long term holding rather than immediate laundering. The affected addresses typically held coins for years, meaning many victims believed they were in safe, long term cold storage before being drained in minutes.
2. Why The Firmware Bug Is So Dangerous
The thefts stem from a Coldcard firmware change released on 17 March 2021 that silently rerouted seed generation from a dedicated hardware random number generator to a weaker, predictable software source. Analyses by Galaxy and others show that all stolen coins were created after this firmware release, and none before it, which effectively fingerprints the bug as the attack vector. The reduction in entropy shrank the key space sharply, allowing attackers to reconstruct private keys for affected seeds without physical access to the device, then sweep funds programmatically. Coinkite has shipped fixed firmware, but crucially, updates cannot strengthen seeds already generated with weak randomness, so affected users must generate fresh seeds and migrate funds to truly secure wallets.
3. Broader Hardware Wallet Risk Trend
The Coldcard incident sits alongside a wider pattern of hardware wallet problems. SafePal recently disclosed an order system flaw that exposed personal data for about 40,000 customers, part of a broader run of hardware wallet incidents and over $100 million in Coldcard related Bitcoin losses, increasing phishing and targeting risk for identified holders. At the same time, malware campaigns like the Lumma Stealer infostealer, delivered via pirated The Odyssey downloads, specifically harvest wallet credentials and seed phrases from desktop and mobile wallet apps, according to security analyses. Together, firmware bugs, data leaks and infostealing malware show that self custody depends not just on the device, but on the whole security stack around it.
For Bitcoin holders, hardware wallets remain useful but not magically safe; real security comes from strong key generation, up to date firmware, careful migration when flaws are found, and minimizing how much personal data is linked to your on chain holdings.
Conclusion
Hardware wallet attacks that exploit Coldcards firmware bug have already driven more than $115 million in Bitcoin losses, proving that even offline devices can fail if their key generation logic is flawed. Combined with rising data breaches and targeted malware, the lesson for crypto users is that self custody is powerful but demands ongoing scrutiny of both wallet design and personal security practices, not blind trust in any single device or brand.
