Coldcard firmware flaw tied to $111M+ in Bitcoin thefts
AI Market Summary
A disclosed firmware RNG flaw in Coinkite's Coldcard (v4.0.1) enabled attackers to brute-force low-entropy seeds and drain ~1,596–1,719 BTC (>$100M), with evidence of multiple coordinated theft waves and thousands of affected addresses. While this is not a Bitcoin protocol issue, it undermines self-custody confidence and can prompt near-term risk-off behavior, accelerated wallet migrations, and heightened scrutiny of hardware wallet supply chains and firmware practices.
Impact level
● Medium
Affected assets
BTC/USDT+0.87%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Coldcard, the Bitcoin hardware wallet made by Coinkite, is facing scrutiny after a firmware vulnerability was linked to large-scale thefts. Onchain analysis indicates attackers drained roughly 1,596 to 1,719 BTC from thousands of addresses, with losses estimated at $100 million to $111 million. A suspected fourth wave, flagged around August 3, added about 389 BTC to the total. Galaxy Digital's onchain analysis team, led by Alex Thorn, confirmed the activity through forensic review of blockchain data.
The breach is notable for what it was not: investigators found no evidence of phishing, key leakage, or user mistakes. The issue stemmed from the device firmware itself.
A bug traced to a 2021 firmware release
According to disclosed details, the vulnerability traces back to Coldcard firmware version 4.0.1, released March 17, 2021. That update introduced a defect in the wallet's random number generator, producing seed phrases with far less entropy than expected. Some seeds may have contained as little as roughly 40 bits of entropy, making them feasible to guess with enough computing power.
Attackers reportedly used open-source brute-force tools to reconstruct vulnerable seeds and sweep associated wallets. The issue remained undetected for more than five years.
Coinkite disclosed the vulnerability on July 30, 2026, and released a patched firmware version the next day. Even so, updating firmware cannot restore stolen funds and does not fix seeds generated under the vulnerable firmware. Users affected must create an entirely new seed on updated firmware and move all funds to new addresses.
Galaxy estimates the campaigns involved at least 15 distinct attackers across at least three confirmed waves of theft, targeting roughly 7,300 addresses. As of August 7, confirmed stolen Bitcoin had reached 1,719 BTC. Some reports place potential losses above $130 million when additional suspected activity is included.
Onchain behavior suggests stolen funds largely idle
Galaxy's review also found that most of the stolen BTC remains unspent onchain. While attackers have moved funds, they have not yet dispersed or converted them in patterns commonly associated with laundering.
The timing and repetition of the theft waves stand out. Three confirmed waves were followed by a suspected fourth, pointing to coordinated exploitation rather than a single one-off discovery. The presence of at least 15 distinct attackers suggests the vulnerability may have been shared or sold prior to public disclosure.
Implications for self-custody users
Coldcard has been positioned as a security-first device, popular with technically experienced Bitcoin holders who prefer self-custody over leaving funds on exchanges. The incident underscores that even best-practice users can be exposed by failures in trusted security tools.
Users holding funds on Coldcard devices running firmware from version 4.0.1 onward are advised to update immediately, generate a new seed on patched firmware, and migrate funds to new addresses. Delaying increases exposure, particularly if further theft waves occur. The suspected August 3 activity suggests some vulnerable addresses may still be at risk.