BTC $63,085 โ–ผ0.50% ETH $1,879 โ–ฒ0.28% SOL $75.22 โ–ฒ 0.50% XRP $1.02 โ–ฒ 0.90%
Security

Coldcard Hack: $116M in Bitcoin Drained Via 2021 Firmware Flaw

Illustration of compromised Coldcard hardware wallets with $116M loss

Hackers have drained roughly 1,816 BTC โ€” about $116 million โ€” from Coldcard hardware wallets, exploiting a firmware bug that dates back to March 2021, according to blockchain intelligence firm TRM Labs. Four waves of thefts since July 30, 2026 have hit more than 5,200 Bitcoin addresses, making this the largest hardware wallet exploit ever recorded and the third-biggest crypto hack of the year.

The stolen funds are still sitting in a handful of attacker-controlled addresses with almost no laundering attempts so far โ€” and blockchain analysts warn the true scale may grow as more victims discover their wallets were compromised years before the attack began.

Key FactDetails
Total stolen~1,816 BTC (โ‰ˆ $116 million) per Galaxy Research tally
Addresses hit5,200+ across four theft waves starting July 30, 2026
Root causeFirmware v4.0.1 (March 2021) fell back to weak software RNG for seed generation
ImpactEffective key strength dropped from 128 bits to as low as 40 bits on older devices
Who's at riskAnyone who generated a Coldcard seed between March 2021 and the patch
Fix statusUpdating firmware does NOT fix existing seeds โ€” migration required

How the Attack Worked: A Five-Year-Old Bug Weaponized

The vulnerability traces to Coldcard firmware version 4.0.1, released in March 2021. A build configuration error caused some devices to generate their wallet seed โ€” the master key protecting all funds โ€” using a weak software random number generator instead of the hardware secure element's entropy source.

The result: private keys that should have required an impossible 128 bits of randomness could effectively be brute-forced with as little as 40 bits on older devices. Modern computing power can crack those keys remotely, without ever touching the physical device. An attacker simply generates candidate keys matching the weak pattern and sweeps any funded address that responds.

The first wave struck on July 30, 2026: within 25 minutes, roughly 594 BTC (~$38 million) moved out of approximately 500 wallets into a single consolidation address. Three more waves followed over four days, with the fourth still moving through the mempool when TRM Labs published its assessment on August 5.

Who Is Affected โ€” And The Critical Fix That Doesn't Work

Here's the part every Coldcard owner needs to understand: updating to the latest firmware does not protect wallets whose seeds were created on vulnerable firmware. The weak randomness was baked into the seed at creation. Once a seed exists, its strength never improves.

Coinkite, Coldcard's Toronto-based manufacturer, patched the bug after it was identified, but the company faces growing criticism over disclosure timelines. Canadian broadcaster CBC reported this week that the breach has raised fresh questions about how long the weakness went publicly unknown.

On-Chain Forensics: Why Investigators Suspect Multiple Hackers

TRM's tracing shows most victim funds pooling at a small number of attacker addresses. Laundering has been surprisingly minimal: a single 64.9 BTC Wasabi Wallet deposit and 200 ETH sent to Tornado Cash on August 4 are the only notable mixing moves so far.

That restraint is unusual. Professional crews like North Korea's TraderTraitor typically begin aggressive laundering within hours. Differences in how each wave's transactions were constructed have led TRM to suspect multiple independent attackers exploited the same bug rather than one organized crew โ€” which is why no attribution has been made yet.

In a surreal twist, analysis of OP_RETURN data โ€” Bitcoin's tiny message field โ€” revealed spam messages directed at the hackers themselves, including one offering laundering services for a 7% fee. Whether genuine or a scam targeting the thieves, it shows how fast illicit service providers move to capitalize on headline breaches.

What This Means for Self-Custody Believers

2026 has already produced major DeFi exploits and exchange breaches โ€” totaling over $1.2 billion hacked across 276 incidents year-to-date. But the Coldcard case hits differently because hardware wallets are the option people choose precisely because they're supposed to be the safest.

The lesson is uncomfortable: self-custody relocates risk; it doesn't eliminate it. A wallet is only as trustworthy as the process that generated its keys. Security researchers now emphasize multisignature setups that combine independently designed devices โ€” so a flaw in one manufacturer's entropy generation can't compromise everything.

Cold storage remains vastly safer than leaving coins on an exchange. But "not your keys, not your coins" now carries a footnote: make sure those keys were generated properly in the first place.

Frequently Asked Questions

Is my Coldcard wallet safe?

If your seed was generated between March 2021 (firmware 4.0.1) and the patch, assume compromise. Seeds created outside that window on updated firmware follow normal security assumptions. When in doubt, migrate to a new seed โ€” transferring funds to a freshly generated wallet takes minutes.

How did hackers drain wallets without physical access?

The weakened randomness shrank the possible key space dramatically. With enough computing power, attackers brute-force private keys mathematically and sweep balances directly on-chain โ€” the device itself is never touched or needed.

Will Coinkite reimburse victims?

No reimbursement program has been announced. Hardware wallet vendors' terms typically disclaim liability for lost funds, which is why security advocates recommend multisig across different manufacturers for large holdings.

What's the total crypto hacked in 2026?

Over $1.2 billion across 276 incidents year-to-date, per TRM Labs โ€” and the Coldcard exploit alone accounts for roughly $116 million of that, ranking as the year's third-largest hack.

Sources