Coldcard Loss Raises Concerns After $112 Million Bitcoin Theft

Add as a preferred source on Google

The Coldcard security breach has resulted in more than 1,778 BTC being stolen from thousands of wallets after attackers exploited a long-standing firmware vulnerability. The incident has raised fresh concerns about hardware wallet security, seed phrase generation, and the risks of cryptocurrency self-custody.

The Coldcard loss incident is arguably the biggest case of hardware wallet security breach in crypto space history, as hackers managed to steal over 1,778 bitcoins valued at about $112 million from over 5,000 wallets.

The security breach began on July 30, 2026, as a result of a loophole in the Coldcard firmware that made hackers able to exploit wallets created using compromised software.

The theft happened rather fast. In just 41 minutes, over 1,000 BTC had been stolen from over 1,000 wallets. In mid-August, about 1,531 BTC were still available in wallets owned by the hackers.

weekly-research-brief
Source: galaxy.com

Coldcard Loss Linked to a 2021 Firmware Problem

The Coldcard loss has been attributed to the firmware version 4.0.1, which was released by Coinkite in March 2021. The bug was caused by the faulty generation of seed phrases within the Coldcard devices through the new update.

Seed phrases are essential, as they are necessary for the generation of private keys that will be used to access an individual’s cryptocurrency. The Coldcard devices are supposed to generate the seed phrases using a hardware random number generator.

This was a huge security threat because predictable randomness could compromise the generation of cryptographic keys. It is said that the flaw persisted for many years without any solution.

As stated by Galaxy Research, there had been complaints raised to Coinkite about a related problem back in May 2025. Eventually, the attackers found a way to exploit the vulnerability on a massive scale.

Several Coldcard devices were vulnerable to this attack; namely, the Mk2, Mk3, Mk4, Q, and Mk5 devices. In addition, the attackers who exploited this vulnerability were at least 12.

Also Read | Cboe SEC Approval Sought for 3x Bitcoin and Ethereum ETFs

Coinkite Issues Security Fix

The security advisory from Coinkite came out on July 30, the very same day when these attacks started. The patched firmware was ready for distribution on July 31, and Rodolfo Novak, the CEO of Coinkite, issued an apology for what had happened.

This, however, is not the solution for the users whose seed phrases had been generated by the vulnerable software.

Coinkite has suggested that the users create an entirely new seed phrase, using the patched firmware, and then move their money into the new wallet. The seed generated through vulnerable firmware is still compromised even after the firmware update today.

Coldcard Loss Raises Self-Custody Questions

A Coldcard loss shows the risks linked to cryptocurrency self-custody. Hardware wallets are designed to protect funds, but firmware vulnerabilities can cause major losses.

The Coldcard loss raises concerns about random number generation testing and security report handling in hardware wallets.

The Coldcard loss highlights the need for stronger firmware security and better vulnerability testing. For Coldcard owners, it is very important to determine whether a certain seed has been generated using the affected firmware or not.

Also Read | CLARITY Act Approval Chances Fall Sharply Ahead of Senate Return

Zagham Abbas

Zagham Abbas

Zagham Abbas is a Blockchain Infrastructure Reporter at Tron Weekly with over five years of experience covering cryptocurrency markets, blockchain infrastructure, and digital asset regulation. His reporting focuses on core blockchain networks, protocol-level developments, decentralized finance ecosystems, and major assets such as Bitcoin, Ethereum, and altcoins.
Zagham covers network upgrades, protocol changes, scalability developments, security incidents, and ecosystem adoption across leading blockchain platforms. He also provides market analysis, explaining how infrastructure updates and regulatory actions impact digital asset markets. His work delivers clear, fact-based reporting for both beginners and experienced readers. He holds a Bachelor of Arts degree and follows strict editorial and fact-checking standards at Tron Weekly.

Articles: 1208