
A flaw in Coldcard hardware wallets let attackers drain bitcoin from thousands of addresses, and the losses kept climbing as the scope widened.
Quick Take
- Galaxy Research tied the opening wave to 1,082.65 BTC, worth about $70.2 million, taken from 1,196 addresses in 41 minutes.
- Later reporting said the total rose to about 1,367 BTC, or nearly $89 million, across 4,585 addresses after two more waves.
- Researchers and reporters traced the problem to a Coldcard seed-generation flaw that began with firmware changes in March 2021.
- Coinkite warned users to update affected devices while investigators kept watching for more thefts.
How the Attack Unfolded
The first wave hit fast. On July 30, attackers swept bitcoin from 1,196 addresses in a 41-minute window, taking 1,082.65 BTC and leaving a clear on-chain trail for Galaxy Research to follow. That opening burst looked like a single coordinated event, but it turned out to be only the start.
Later analysis showed two more suspected waves, which pushed the total losses much higher and spread the damage across far more wallets.
By early August, the running total had reached about 1,367 BTC, or nearly $89 million, across 4,585 addresses. That scale made the incident one of the largest hardware-wallet thefts in recent memory.
Coindesk reported the third wave alone drained about 208 bitcoin from 1,912 addresses, showing that smaller balances were also being targeted. The pattern suggests a methodical campaign, not a one-time smash-and-grab.
Where the Weakness Came From
Multiple reports point to a flaw in how Coldcard generated wallet seeds, the starting material that protects a Bitcoin wallet. The bug reportedly dated to a March 2021 firmware change and could cause the device to fall back to weak, deterministic software random number generation instead of the hardware random number generator.
That matters because if the seed is predictable, the private key can be reproduced offline and the wallet can be emptied without touching the device.
BREAKING: 🚨 A suspected fourth wave of attacks linked to the Coldcard wallet vulnerability may have pushed total losses to 1,816 BTC, worth roughly $114 million.
More than 5,200 addresses may be affected since July 30. pic.twitter.com/h6cs8mIjUV
— Crypto Pay (@cryptopaydotcom) August 3, 2026
Coinkite’s warning focused on affected firmware ranges and urged users to update as soon as possible. Reporting also said the problem may affect several Coldcard model lines, not just one version. That broader reach is what makes the episode unsettling.
A tool marketed for cold storage is supposed to be the last place a thief can reach, yet a seed flaw turned that promise into a trap for users who thought they had done everything right.
Why This Story Matters
This attack fits a familiar crypto pattern: one technical flaw, then a rapid wave of forensic reporting, then a bigger number as more wallets are linked to the same weakness. That is why the first loss estimate was not the final one. The important lesson is plain.
Hardware wallets are only as strong as the code that creates the keys inside them. If that code fails, the physical shell offers little comfort.
I think many are still shocked and might not have a clear understanding of what happened here but let me explain.
A firmware flaw introduced in March 2021 caused Coldcard devices to skip their hardware randomness generator and fall back to predictable software-based key… https://t.co/VAWGNmRnxi
— Emmanuel Brighton (@SBE_PENXCHAIN) August 2, 2026
For bitcoin owners, the immediate question is whether their own seed was generated during the vulnerable period. For the wider market, the larger question is trust. People buy cold storage because they want fewer moving parts and fewer chances for human error.
This case shows that the weakest link can hide at the very beginning, long before anyone sends a coin, and that is the part many users never think to test.
Sources:
foxbusiness.com, thehackernews.com, cryptopolitan.com













