Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Coldcard Bitcoin hardware wallet breach results in over $115 million in losses
00

Coldcard Bitcoin hardware wallet breach results in over $115 million in losses

Aug 16, 2026

A critical firmware vulnerability in Coinkite's Coldcard Mk3 hardware wallets has resulted in over $115 million in stolen Bitcoin, affecting 8,680 addresses since July 30, 2026. The flaw, which went undetected for five years, caused the devices to generate weak cryptographic keys using serial numbers and internal clocks instead of a hardware random number generator. Galaxy Research reports that Wave 1 alone drained $70.2 million in under an hour, with some trackers estimating total losses could exceed $130 million.

Coldcard firmware vulnerability

  • ▪Coinkite ran an advanced artificial intelligence model over the Coldcard codebase weeks before the July 2026 theft, but the security review failed to detect the vulnerability.
  • ▪Coinkite's Coldcard Mk3 hardware wallets shipped with a flawed firmware version 4.0.1 on March 17, 2021, which silently went undetected for five years.

Bitcoin theft exceeds $115 million

  • ▪Cryptocurrency tracker Twenty-One Million reported that some estimates place the total losses from the Coldcard exploit at over $130 million.
  • ▪The initial Wave 1 sweep on July 30, 2026, drained 1,082.65 Bitcoin, valued at approximately $70.2 million, from 1,195 addresses in under an hour.
  • ▪Galaxy Research reported that Coldcard hardware wallet losses exceeded $115 million, representing 1,778.58 Bitcoin swept from 8,680 addresses between July 30 and August 13, 2026.

Weak randomness cryptographic flaw

  • ▪The Coldcard vulnerability occurred because a safety check failed to detect that the hardware generator was disabled, forcing seed generation to fall back to a weak software generator.
  • ▪Attackers exploited the weak randomness by pre-calculating possible keys and matching them to active Bitcoin addresses on the blockchain without requiring physical access to the devices.
  • ▪The software fallback used the device's serial number and internal clock, reducing the entropy of the Coldcard Mk3 seed generation from 128 bits to about 40 bits.

Victim support efforts

  • ▪Galaxy Research contacted more than 200 victims of the Coldcard exploit to offer support and gather intelligence on the attackers.
  • ▪Only 192 victims formally reported losses to Galaxy Research, representing 714.81 Bitcoin, while the remaining 6,890 drained addresses have no named owner.

Attacker intelligence gathering

  • ▪Galaxy Research estimated that at least 15 separate attackers independently exploited the Coldcard firmware vulnerability.
  • ▪The attackers targeted inactive addresses, with the stolen Bitcoin having sat untouched for a median of 1,292 days, and 88% of the funds being at least one year old.

Hardware wallet security failures

  • ▪The Coldcard incident demonstrated that offline storage devices remain vulnerable to asset theft if the software used to generate cryptographic keys contains a flaw.
  • ▪Cryptocurrency tracker Twenty-One Million described the Coldcard exploit as one of the largest hardware-wallet failures in Bitcoin's history and a major crypto theft of 2026.

5 sources

Hindustantimes
Why bitcoin could lose its edge to AI stocks over the next 5 years
View source article
Pymnts
Coldcard Breach Losses Now Exceed $115 Million | PYMNTS.com
View source article
Beincrypto
Coldcard Losses Pass $115 Million, Galaxy Research Data Shows
View source article
Bitcoinmagazine
Losses Top $115M In Coldcard Bitcoin Hack: Galaxy Research
View source article
Thenationalnews
How a hidden flaw in Coldcard wallets led to an $88.6m Bitcoin theft | The National
View source article

Story comments

Loading comments…

Related Projects

Galaxy ResearchBitcoin

Topics

Bitcoin wallets & custodyBitcoin security & risksHardware wallet vulnerabilitiesBitcoin