Coldcard's five-year-old firmware flaw let attackers brute-force wallet seeds, draining $116 million while 233,000 bitcoin moved to safer custody.
Coldcard's five-year-old firmware flaw let attackers brute-force wallet seeds, draining $116 million while 233,000 bitcoin moved to safer custody.

An attacker drained 1,816 bitcoin, worth about $116 million, from more than 5,200 Coldcard wallets starting July 30, exploiting a five-year-old firmware flaw that weakened seed randomness.
"The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class," Nick Neuman, chief executive at Casa, said in an Aug. 9 post on X.
Galaxy Research's running tally puts losses near 1,816 BTC across four waves of theft, with the first sweep moving roughly 594 BTC from about 500 wallets into a single consolidation address within 25 minutes. The vulnerability traces to firmware version 4.0.1, released in March 2021, where a build configuration error caused some devices to fall back on a weak software random number generator instead of the hardware-based entropy source. Effective key strength collapsed from a designed 128 bits to as little as 40 bits on older devices, low enough to brute force without physical access.
The incident marks the third-largest attack of 2026, pushing total hacked value past $1.2 billion across 276 incidents, and has triggered a broader reassessment of single-key hardware wallets. Neuman cited Checkonchain data showing 233,000 BTC left long-term holder wallets and 22,000 BTC moved to exchanges in the days after the exploit, with Casa customer flows indicating single-key Ledger and Trezor users shifting to multisig and multisig users removing Coldcard devices from their keysets.
Galaxy Research tracked the initial wave draining 1,082.65 BTC, worth about $70 million, from 1,196 addresses over a 41-minute window on July 30, tracing the funds to four attacker-controlled addresses. A second and third wave on Aug. 1 pushed the total to 1,367 BTC, about $88.6 million, across 4,385 addresses, with a fourth wave still moving through the mempool at the time of TRM Labs' assessment.
TRM's on-chain tracing shows most victim funds pooling at a small number of attacker-controlled addresses, with laundering limited to a single 64.9 BTC Wasabi deposit and 200 ETH sent to Tornado Cash on Aug. 4. Where funds moved past the initial receiving address, it amounted to a single hop of consolidation rather than layering or mixing, suggesting attackers may still be working out how to move a sum large enough to attract attention. Differences in transaction construction across the waves hint multiple attackers may be at work, and TRM is not attributing the theft to a specific actor.
Analysis of OP_RETURN fields found spam messages directed at the hackers, including one offering to launder the stolen funds for a 7 percent fee, illustrating how quickly illicit service providers sought to capitalize on the incident.
Coinkite has released updated firmware for every affected model and track, but the fix protects only future wallet creation. Seeds generated on Mk2 or Mk3 devices running version 4.0.1 through 4.1.9 remain at risk unless created with at least 50 independent dice rolls and protected by a strong BIP-39 passphrase, while Mk4, Q and Mk5 devices generated seeds with about 72 bits of entropy rather than the expected 128 bits.
Neuman argued the scale of the response shows self-custody's resilience. "If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped," he said. "As it was, the thieves had to crack one wallet at a time, earning a little BTC each wallet, instead of cracking one wallet and getting a massive payday."
The incident reinforces that a wallet is only as trustworthy as the process that generated its key, making firmware and entropy generation as critical to scrutinize as the device itself. Multisignature setups that combine independently designed devices and independently generated entropy reduce reliance on any single implementation. Anyone who generated a Coldcard seed between March 2021 and the recent patch should treat that seed as compromised, generate a new one on updated hardware, and migrate funds beginning with a small test transaction.
This article is for informational purposes only and does not constitute investment advice.