Coldcard Hack Exposed: How a 5-Year-Old Bug Drained $116M in Bitcoin
Admin
Coldcard Security Breach: How Hackers Drained $116 Million in the Latest Hardware Wallet Exploit Hackers have stolen roughly 1,816 bitcoin — worth close to $116 million — from more than 5,200 addresses generated on Coldcard hardware wallets, in what researchers are calling the most damaging cold-storage failure in the industry's history. The attacks began on July 30, 2026, and unfolded across four separate waves over the following days, according to blockchain intelligence firm Galaxy Research. The breach has unsettled a corner of the crypto market that has long marketed itself as immune to exactly this kind of theft.
What happened Coldcard, made by Canadian firm Coinkite, is a small offline device that stores the private keys protecting a user's bitcoin, keeping them away from internet-connected computers and phones. It is marketed as cold storage for long-term holders, and until now it had a reputation as one of the more security-conscious products in the space. That reputation is now central to why this incident has drawn so much attention.
The first sweep moved about 594 BTC, worth close to $38 million at the time, out of roughly 500 wallets within 25 minutes. A separate accounting from Galaxy Research put the opening wave at 1,082.65 BTC from 1,196 addresses drained in 41 minutes, and the figures have continued shifting as researchers track additional wallets. By Monday, an analysis from Galaxy Research counted three confirmed waves plus a number of smaller incidents totaling 1,596 bitcoin from roughly 7,300 addresses, with a suspected fourth wave that could push the total toward 2,055 BTC, or around $130 million. The number affected keeps growing as more compromised wallets are identified, which is part of what has made the incident so difficult to contain.
The technical flaw The root cause traces back five years. Coldcard firmware version 4.0.0, shipped in March 2021, quietly bypassed the device's dedicated hardware randomness chip during key generation and substituted a predictable software alternative instead. That flaw made it possible, in theory, to enumerate the seed phrases that protect a wallet's funds.
Investigators at Block traced the fault to a production configuration that disabled the hardware random-number generator because Coinkite supplies its own wrapper for it — but a supporting code library checked only whether that setting existed, not whether it was actually turned on, which routed key generation to MicroPython's fallback generator instead. That fallback initialized itself using the chip's unique ID and timer data and never gathered fresh entropy afterward. Coinkite estimates the effective randomness fell to roughly 40 bits on the Mk3 model and about 72 bits on the Mk4, Mk5 and Q, compared with the 128 bits expected from a standard 12-word seed phrase — a gap wide enough for a well-resourced attacker to brute-force.
Crucially, victims did not need to be phished and no device was physically stolen; attackers essentially learned how to reproduce the keys directly. That distinction matters because it undercuts the basic premise of cold storage: that keeping a device offline and never sharing its seed phrase is enough to stay safe.
Response and reactions Coinkite confirmed the scope of the bug and told affected users to move their funds immediately. In a public advisory, the company urged customers to treat the situation as urgent and migrate holdings without delay. In a separate open letter, Coinkite described the preceding days as among the hardest in the company's history for itself and, for many readers, something worse. Coldcard's CEO Rodolfo Novak has floated the idea that AI-assisted code review might increasingly surface this kind of latent bug, though independent security researchers have generally attributed the flaw to ordinary human engineering error rather than anything novel.
Ido Ben-Natan, chief executive of security firm Blockaid, noted that a hardware wallet's real security depends on firmware and internal systems that users never actually see. That point has resonated widely, given that many victims followed every standard precaution — never exposing their seed phrase, never connecting the device to the internet — and were compromised anyway.
According to TRM Labs, this ranks as the third-largest crypto hack of 2026 and pushes the year's total stolen funds past $1.2 billion across 276 incidents. Notably, the stolen bitcoin has largely stayed put in a small number of attacker-controlled addresses, with little evidence so far of mixing or layering to obscure the trail.