Coldcard Hardware Wallet Flaw Linked to Nearly $90 Million in Bitcoin (BTC) Thefts Across 4,500 Addresses

A critical vulnerability in certain Coldcard hardware wallets has led to substantial Bitcoin losses, with researchers tracking approximately 1,367 BTC drained from more than 4,500 addresses. The estimated value of the stolen funds has climbed toward $90 million as of early August 2026, according to on-chain analysis.

Galaxy Research identified three distinct waves of activity linked to addresses believed generated on vulnerable Coldcard devices.

The first and largest wave occurred on July 30, sweeping roughly 1,083 BTC from about 1,200 addresses in a rapid 41-minute window. Subsequent waves on July 31 and August 1 added further losses, bringing the cumulative observed total to 1,367 BTC across 4,585 addresses.

Many of the affected wallets held long-dormant coins, with average inactivity exceeding three years, pointing to long-term holders as primary victims.

The root issue stems from a firmware defect introduced in March 2021.

On affected Coldcard models, particularly Mk2 and Mk3 devices running versions from 4.0.1 onward, and to a lesser extent earlier firmware on Mk4, Mk5, and Q models, the random number generator failed to deliver the intended entropy.

Instead of producing truly unpredictable seed phrases with 128 bits of security, the devices generated seeds from a far smaller, more guessable set of possibilities.

Attackers could therefore compute likely seeds offline, derive the corresponding Bitcoin addresses, and check the blockchain for funded matches—all without physical access to any wallet or any interaction with the devices themselves.

Only single-signature wallets appear impacted. Multisignature setups and those protected by strong BIP-39 passphrases have so far shown greater resilience.

Users who incorporated sufficient independent dice rolls (at least 50 private, fair rolls) during seed creation also fall outside the primary risk category, as that external entropy compensated for the device shortfall.

Coinkite, the Canadian manufacturer of Coldcard, issued a security advisory shortly after the initial drains and has released fixed firmware for all affected models.

Updating the software prevents new seeds from inheriting the flaw, yet it cannot repair seeds already generated under the vulnerable code.

Owners of potentially exposed wallets are strongly advised to generate entirely new seeds on updated devices or alternative secure hardware and carefully migrate their funds after verifying backups and testing small transfers.

The incident underscores a fundamental principle of self-custody: the security of a hardware wallet ultimately rests on the quality of its seed generation. Even air-gapped devices and secure elements cannot protect keys that an attacker can recreate through pure computation.

Security researchers continue monitoring the blockchain for additional activity, noting that the exploit remains ongoing for any remaining vulnerable single-signature addresses.

Industry observers have flagged hundreds of suspected attacker-controlled addresses to authorities and compliance teams.

The stolen bitcoin has largely remained unspent in collector wallets so far. Affected users and those who may have generated seeds on Coldcard devices since early 2021 should consult official guidance immediately and prioritize migration to eliminate residual risk.



Sponsored Links by DQ Promote

 

 

0 0 votes
Article Rating
Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Newest
Oldest Most Voted
 
0
Would love your thoughts, please comment.x
()
x
Send this to a friend