A four-year-old firmware flaw in Coldcard hardware wallets let attackers drain more than $112.7 million in Bitcoin from over 8,600 addresses, shaking confidence in self-custody.
A four-year-old firmware flaw in Coldcard hardware wallets let attackers drain more than $112.7 million in Bitcoin from over 8,600 addresses, shaking confidence in self-custody.

A four-year-old firmware flaw in Coldcard hardware wallets let attackers drain more than $112.7 million in Bitcoin from over 8,600 addresses, shaking confidence in self-custody.
Attackers drained at least 1,778.84 Bitcoin, worth $112.7 million, from over 8,600 Coldcard addresses after a four-year firmware bug went unfixed.
Galaxy Research, which tracked the theft, said at least 15 attackers exploited the vulnerability without physical access to the devices, and confirmed losses may climb to 2,417.35 Bitcoin, or about $153 million, once unconfirmed episodes are counted.
The flaw traced to firmware version 4.0.0, released by Coinkite in March 2021. The code checked only whether a random-number generator setting existed, not whether it was enabled, causing devices to silently fall back to a predictable software generator instead of the higher-security hardware random-number generator. Bitcoin developer James O'Beirne reported the defect to Coinkite during a code audit in May 2025, but the company dismissed it, saying a real problem would already have been discovered.
Coinkite has distributed patched firmware for all affected Coldcard models, but the update only protects seeds generated in the future. Affected users must generate new seeds and move Bitcoin from old addresses, a process that pushed more than 22,000 Bitcoin to centralized exchanges in the first four days after the attack began July 30.
Of the roughly 1,778 Bitcoin confirmed stolen, about 1,531 Bitcoin remain at addresses controlled by the attackers, Galaxy said. Another 246 Bitcoin has moved since the theft, with about 65 percent routed through CoinJoin transactions that complicate tracing and the rest through on-chain peel chains, a laundering pattern in which small amounts are repeatedly stripped from a large sum.
Galaxy shared the hackers' address lists with exchanges, compliance firms and law enforcement to block or freeze stolen assets reaching centralized platforms. No multisignature wallets were compromised, showing the added security of requiring multiple approvals per transaction. The theft ranks as the twentieth largest in cryptocurrency history, just below Multichain's $130 million breach and above Harmony's $100 million Horizon bridge hack.
Galaxy believes at least some attackers likely used AI models without strict cybersecurity guardrails, including Chinese open-source large language models such as Kimi K3. The deployment of unrestricted AI for malicious purposes outpaced defensive capabilities, with strict safety rules at major U.S. AI labs hampering defenders' access to equally capable countermeasures.
The incident has dealt a blow to the self-custody narrative. Victims were mostly users who kept Bitcoin in hardware wallets, long considered one of the safest storage methods. By Aug. 8, combined balances on exchanges reached 3.683 million Bitcoin, an all-time high, as users moved funds off vulnerable devices. The breach follows a run of hardware-wallet incidents this year, including data exposures at SafePal affecting about 40,000 customers, Trezor affecting nearly 14,000, and Ledger through a third-party payment provider.
This article is for informational purposes only and does not constitute investment advice.