Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Coldcard Bitcoin wallet exploit losses exceed $100 million across multiple attack waves
00

Coldcard Bitcoin wallet exploit losses exceed $100 million across multiple attack waves

Aug 2, 2026

A five-year-old firmware bug in Coldcard hardware wallets has led to over $100 million in Bitcoin being stolen across multiple attack waves. The flaw caused devices to use a weak random number generator, allowing attackers to reconstruct private keys. The exploit, affecting thousands of users, has prompted manufacturer Coinkite to issue patches and has triggered a market reaction not seen since the FTX collapse, reigniting debates on self-custody.

Coldcard vulnerability discovery

  • ▪A firmware flaw in Coinkite's Coldcard hardware wallets, originating in a March 2021 build, allowed attackers to reconstruct Bitcoin private keys offline
  • ▪The vulnerability affects Coldcard's Mk2, Mk3, Mk4, Mk5, and Q devices with single-key seeds, but not multisignature setups

Random number generator flaw

  • ▪The firmware error caused devices to use a predictable software randomizer (MicroPython's Yasmarang) instead of the intended hardware random number generator (RNG)
  • ▪The flaw reduced the effective entropy from a target of 128 bits to as low as 40-72 bits, allowing attackers to brute-force seed phrases

Attack timeline

  • ▪A fourth attack wave used Bitcoin's "replace-by-fee" feature, giving some victims a chance to outbid the attacker and save their funds
  • ▪The first attack wave began on July 30, 2026, with subsequent waves continuing through at least August 2, 2026

Theft losses

  • ▪The loss profile consists mainly of many small, individual self-custody accounts, not large institutional holdings
  • ▪Confirmed losses from the exploit have exceeded $100 million, with 1,596 BTC stolen from approximately 7,300 addresses across multiple incidents
  • ▪Including a suspected but unconfirmed fourth wave, Galaxy Research estimates total losses could reach 2,055 BTC, worth about $130 million

Coinkite disclosure response

  • ▪Coinkite, the maker of Coldcard, acknowledged the bug, released emergency firmware patches, and advised users to move funds to new wallets
  • ▪Coinkite initially understated the scope of the vulnerability, first claiming only Mk3 devices were affected before including Mk4, Mk5, and Q models
  • ▪Some users reported their devices "bricking" during the new firmware update process, complicating the recovery of funds

Market reaction and investigation

  • ▪As of August 4, 2026, 90% of the stolen Bitcoin remained unmoved from the initial attacker addresses
  • ▪In a reversal of the post-FTX trend, some users moved funds from self-custody onto centralized exchanges for perceived safety
  • ▪Attacker and victim addresses have been shared with US federal law enforcement, and blockchain analysis firms are monitoring the stolen funds
  • ▪The incident reignited a debate on the risks of self-custody, with some advocating for wallet diversification or the use of centralized platforms
  • ▪The exploit triggered a spike in small Bitcoin transfers to 39,600 BTC on July 31, a level not seen since the 2022 FTX collapse

16 sources

Bloomberg
Hackers Hit Bitcoin’s Safest Hiding Place in Ongoing Attack
View source article
Coindesk
Unlike the FTX collapse, the $89 million Coldcard exploit has investors sending bitcoin back to exchanges
View source article
Fortune
Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit | Fortune
View source article
Protos
A timeline of Coldcard's $85M bitcoin theft
View source article
Beincrypto
$1.6 Million Drained in a Blink: User Recounts His Dramatic Coldcard Wallet Hack
View source article

Story comments

Loading comments…

Related entities

Bitcoin

Topics

Hardware wallet securityCryptoBitcoin security & risksCryptocurrency theftCrypto hacksBitcoin wallets & custody