Coldcard Hardware Wallet Exploit Drains Over $100 Million in Bitcoin
Coldcard, the Canadian‑made hardware wallet from Coinkite, fell victim to a firmware flaw that has allowed attackers to siphon more than $100 million worth of Bitcoin from users’ offline wallets. The vulnerability, discovered in July 2026, stems from a five‑year‑old bug that caused the device’s seed‑generation process to use a weak pseudo‑random number generator (PRNG) instead of the hardware true random number generator (TRNG) that should have been employed.
The flaw was introduced in March 2021 when a conditional compilation directive silently swapped the TRNG for a non‑cryptographic PRNG. Because the seed phrase is the single piece of information that can unlock a wallet, the predictable pattern made it possible for anyone who had a sample seed phrase to generate the same seed for every vulnerable device. Attackers could therefore reconstruct the private keys of thousands of wallets without ever touching the hardware.
The first wave of the attack began on July 30, 2026. Within 25 minutes, approximately 594 BTC—about $38 million at the time—had been moved from roughly 500 Coldcard wallets into a single consolidation address. Subsequent waves have continued to sweep funds from more wallets. By early August, Galaxy Research reported that 1,816 BTC, worth roughly $116 million, had been drained from more than 5,200 addresses. Other estimates place the total at 1,367 BTC, or about $89 million, and a separate count lists 7,300+ addresses affected.
The on‑chain activity generated by the exploit has been significant. According to CoinMarketCap, the hack has driven about 890 kBTC of weekly Bitcoin movement, a level that has pushed on‑chain activity to a 2026 high. The theft has also fragmented into multiple waves, with at least 15 separate attackers identified by Galaxy Research. The most recent wave, reported on August 4, saw a sweep rate 45 times the baseline, indicating that the exploit is still actively being used.
Coldcard’s market share is relatively small, accounting for less than 2 % of the hardware‑wallet market. The incident has therefore had limited impact on Bitcoin’s price, which has held above $63,000 during the period of the theft. Nevertheless, the breach has raised questions about the reliability of self‑custody solutions. The fact that the victims were security‑conscious Bitcoin holders who kept their funds offline has been described by some observers as a “crisis of faith” in the hardware‑wallet model.
Coinkite has issued a statement acknowledging the vulnerability and has released firmware updates that replace the PRNG with a proper TRNG. The company recommends that users who created seeds with firmware versions 4.0.0–4.1.9 on Mk2 and Mk3 devices, or earlier firmware on Mk4, Q, and Mk5 devices, should move their funds to a new wallet. No evidence suggests that the company’s own devices were compromised; the attack relied solely on the seed‑generation flaw.
The incident underscores the importance of rigorous testing for cryptographic components in hardware wallets. It also highlights the need for users to stay informed about firmware updates and to understand the specific version of software that was running when their seed was first generated.
As of mid‑August, the Coldcard exploit remains active. The number of affected addresses continues to rise, and the total value of stolen Bitcoin is still increasing. Regulators and security researchers are monitoring the situation closely, and the incident may prompt further scrutiny of hardware‑wallet manufacturers.
In summary, the Coldcard hack has exposed a critical weakness in a popular offline storage solution, resulting in the loss of more than $100 million in Bitcoin. The breach has prompted firmware updates, user migrations, and heightened industry awareness of the risks inherent in seed‑generation processes.