Coldcard Wallet Vulnerability Tied to $116 Million Bitcoin Heist
Coldcard, a hardware crypto wallet, contained a bug found in the firmware, allowing attackers to brute force recovery phrases generated by affected devices. Following a software update which disabled one of the device’s primary sources of entropy (randomness), 1,816 BTC (~$116 million) was stolen from user wallets over four separate events. Patched firmware is available through the manufacturer Coinkite. However, individuals with affected wallets should immediately transfer their Bitcoin to newly generated wallets.
Coldcard Recover Phrase Vulnerability Puts Self-Custody Security Under Fire Again
Due to a software update pushed to devices in 2021, Coldcard wallets generated recovery phrases using less than ideal hardware randomness and were vulnerable to being brute forced offline.
Detected in 4 separate events, a total of over 5,200+ addresses were found to have been swept by hackers, totaling 1,816 BTC ($116 million) sent to known hacker-addresses.
Firmware updates have been released by Coinkite. However, due to the vulnerability exposing users’ seed phrases, patching the firmware does not secure an already exposed seed. All users with Coldcard wallets should generate a new crypto wallet, then transfer their funds.
Leaders in the cryptocurrency industry, as well as competing companies, have commented on the heist. Ledger, Trezor and even CZ of Binance contributed to the discussion of self-custody security as opposed to safer centralized cryptocurrency exchanges.
How a Firmware Bug Weakened Coldcard’s Random Number Generation
Coldcard is a hardware wallet made by Canadian company Coinkite. It’s advertised as an air-gapped Bitcoin-only wallet with a focus on security. Coinkite has designed Coldcard to ensure users’ private keys never go online. This attention to security made Coldcard a favorite amongst long-term Bitcoin “hodlers” (crypto slang for investors who buy and hold digital assets long-term, ignoring market volatility). However, a recently discovered vulnerability stemming from Coinkite’s seed-generation process reveals all may not be as secure as originally thought.
According to experts, during a firmware update rolled out in March 2021, Coldcard devices somehow skipped Coinkite’s onboard hardware True Random Number Generator (TRNG). When this happened, Coldcard users were provided a deterministic fallback entropy solution created by software instead of secure hardware.
Since the software fallback was generating mnemonic seed phrases (the 12 or 24 random words used to recover wallets) using mathematically deterministic patterns, it was possible for the attackers to document the shortcuts and reproduce the results on a normal computer. This meant that hackers could pre-calculate candidate seed phrases offline, determine what addresses would be associated with those phrases, and drain balances without needing access to any Coldcards.
Coinkite has since published an urgent open advisory urging all impacted users to move their funds immediately. “The last three days have been some of the hardest in this company’s history, and for a lot of the people reading this, they’ve been something much worse,” Coinkite acknowledged in an official statement.
Timeline of the $116 Million Bitcoin Drain
Transactions were executed during narrow automated timeframes discovered by Galaxy Research and confirmed by on-chain analysis:
- July 30 → Wave 1: 1,196 addresses drained in 41 minutes, 1,083 BTC (≈$70.2M) stolen
- August 1 → Wave 2: Identified as a second sweep by the same attacker, pushing the cumulative total to ~1,477 additional addresses (2,673 total) and ~76 additional BTC (1,158.7 BTC cumulative, ≈$75.1M)
- July 31-August 1 → Wave 3: 1,912 addresses drained over roughly 24 hours (reported by Galaxy Research on August 2), 208 BTC stolen, bringing the cumulative total to 1,367 BTC (≈$88.6M) across 4,585 addresses
- August 3 → Wave 4: Final thefts bring cumulative losses to 1,816 BTC (≈$116M) across 5,200+ addresses
The attacks against Coldcard wallets account for one of the largest successful exploits against a hardware wallet in cryptocurrency history. The hack is one of many that took place during a surge of security breaches across the crypto industry. Blockchain data firm TRM Labs said there were 207 separate cryptocurrency exploits in the first six months of 2026. While this is the highest number of individual exploit incidents recorded in a six-month period, overall losses across the industry declined to $972 million from $2.3 billion in H1 2025.
The Crypto Industry Reacts: Blacklists, Competitors, and the Self-Custody Debate
Even though this loss comes with billions of dollars attached, market-wide prices of Bitcoin and Ethereum haven’t moved too drastically, with each dipping less than 1%. Reactions from across “Crypto X (formerly Twitter)” and the community at large, however, have intensified:
Coldcard Hack Sparks Industry-Wide Response
From the Community: Sky, a well-known figure in crypto, took to X to address the hackers directly, warning them that their stolen haul of 1,816 BTC is now riding on one of the most watched and blacklisted coin stacks of all time. He reminded them that every transaction they make will be monitored closely, essentially meaning they can never access banks or move their coins without paranoia for the rest of their lives. Sky then encouraged the thieves to send back the funds to Coinkite and accept a clean 5% “fee” (white-hat bounty) for their troubles so they can legitimately walk away with some of the money.
Hardware Competitors Reassure Users: Competitors Ledger and Trezor both promptly posted detailed statements assuring users that their products were not vulnerable. According to Ledger’s statement on X, their hardware wallets create entropy through use of a hardware True Random Number Generator (TRNG) that is certified and embedded in a separate Secure Element chip with no unsafe software fallback. Trezor noted that its users’ funds are secure because its codebase is independent of Coldcard’s, and it uses entropy pooled from many sources, including device hardware, host input, and the secure element chip.
CZ & The Great Custody Trade-Off: Discussion about if retail holders are truly ready for self custody has once again been thrown into fierce debate after this hack. Binance founder Changpeng Zhao summed up the sentiment many individual investors find themselves in after this news, noting, “I’m a believer in self-custody, but it puts the burden on you.”
Conclusion: Offline Hardware Devices Reliant on Mathematical Entropy Vulnerable to Attack
Offline hardware wallets are only as strong as the math behind the generation of their keys. Self-custody removes third-party counterparty risk but places full responsibility for safeguarding Bitcoin assets and other digital coins on the software running on the device itself. Coinkite is currently working with law enforcement to identify the individuals who purchased funds on the blacklist. Users who downloaded any of the compromised firmware versions should move their funds to a new device with a newly generated seed phrase as soon as possible.