Loading live prices...
Crypto News

Coldcard Hack Exposed: How a 5-Year-Old Bug Drained $116M in Bitcoin

Admin

August 9, 2026
Coldcard Hack Exposed: How a 5-Year-Old Bug Drained $116M in Bitcoin

Coldcard Security Breach: How Hackers Drained $116 Million in the Latest Hardware Wallet Exploit Hackers have stolen roughly 1,816 bitcoin — worth close to $116 million — from more than 5,200 addresses generated on Coldcard hardware wallets, in what researchers are calling the most damaging cold-storage failure in the industry's history. The attacks began on July 30, 2026, and unfolded across four separate waves over the following days, according to blockchain intelligence firm Galaxy Research. The breach has unsettled a corner of the crypto market that has long marketed itself as immune to exactly this kind of theft.

What happened Coldcard, made by Canadian firm Coinkite, is a small offline device that stores the private keys protecting a user's bitcoin, keeping them away from internet-connected computers and phones. It is marketed as cold storage for long-term holders, and until now it had a reputation as one of the more security-conscious products in the space. That reputation is now central to why this incident has drawn so much attention.

The first sweep moved about 594 BTC, worth close to $38 million at the time, out of roughly 500 wallets within 25 minutes. A separate accounting from Galaxy Research put the opening wave at 1,082.65 BTC from 1,196 addresses drained in 41 minutes, and the figures have continued shifting as researchers track additional wallets. By Monday, an analysis from Galaxy Research counted three confirmed waves plus a number of smaller incidents totaling 1,596 bitcoin from roughly 7,300 addresses, with a suspected fourth wave that could push the total toward 2,055 BTC, or around $130 million. The number affected keeps growing as more compromised wallets are identified, which is part of what has made the incident so difficult to contain.

The technical flaw The root cause traces back five years. Coldcard firmware version 4.0.0, shipped in March 2021, quietly bypassed the device's dedicated hardware randomness chip during key generation and substituted a predictable software alternative instead. That flaw made it possible, in theory, to enumerate the seed phrases that protect a wallet's funds.

Investigators at Block traced the fault to a production configuration that disabled the hardware random-number generator because Coinkite supplies its own wrapper for it — but a supporting code library checked only whether that setting existed, not whether it was actually turned on, which routed key generation to MicroPython's fallback generator instead. That fallback initialized itself using the chip's unique ID and timer data and never gathered fresh entropy afterward. Coinkite estimates the effective randomness fell to roughly 40 bits on the Mk3 model and about 72 bits on the Mk4, Mk5 and Q, compared with the 128 bits expected from a standard 12-word seed phrase — a gap wide enough for a well-resourced attacker to brute-force.

Crucially, victims did not need to be phished and no device was physically stolen; attackers essentially learned how to reproduce the keys directly. That distinction matters because it undercuts the basic premise of cold storage: that keeping a device offline and never sharing its seed phrase is enough to stay safe.

Response and reactions Coinkite confirmed the scope of the bug and told affected users to move their funds immediately. In a public advisory, the company urged customers to treat the situation as urgent and migrate holdings without delay. In a separate open letter, Coinkite described the preceding days as among the hardest in the company's history for itself and, for many readers, something worse. Coldcard's CEO Rodolfo Novak has floated the idea that AI-assisted code review might increasingly surface this kind of latent bug, though independent security researchers have generally attributed the flaw to ordinary human engineering error rather than anything novel.

Ido Ben-Natan, chief executive of security firm Blockaid, noted that a hardware wallet's real security depends on firmware and internal systems that users never actually see. That point has resonated widely, given that many victims followed every standard precaution — never exposing their seed phrase, never connecting the device to the internet — and were compromised anyway.

According to TRM Labs, this ranks as the third-largest crypto hack of 2026 and pushes the year's total stolen funds past $1.2 billion across 276 incidents. Notably, the stolen bitcoin has largely stayed put in a small number of attacker-controlled addresses, with little evidence so far of mixing or layering to obscure the trail.

Why it matters The Coldcard breach lands at a moment when self-custody is increasingly pitched to retail and institutional investors alike as the safer alternative to exchange custody. This incident complicates that narrative. Cold wallets remove exposure to exchange hacks and counterparty risk, but they do not eliminate risk altogether — they simply relocate it to the firmware and entropy generation processes that most users can't independently verify. Bitcoin's price dipped by roughly $2,000 in the days following the first wave before recovering, and the CoinMarketCap Fear and Greed Index has drifted toward fear territory, though broader macro factors, including a hawkish Federal Reserve, are also weighing on sentiment.

What to watch next Expect scrutiny to shift toward how other hardware wallet makers handle entropy generation and whether independent audits catch similar shortcuts before shipping. Watch for Coinkite's response on compensation, which it has not yet offered, and whether affected users pursue legal action. Multisignature setups combining independently designed devices are likely to get renewed attention as a hedge against single-vendor firmware failures. And with Galaxy Research's tally still moving, the final scale of losses — and how many more wallets remain quietly vulnerable — may not be settled for some time.