Geo News
Community curated by people like you
LatestAICryptoHealthWorld AffairsUS Politics
Coldcard hardware wallet exploit prompts mass Bitcoin migration after $130 million hack
00

Coldcard hardware wallet exploit prompts mass Bitcoin migration after $130 million hack

Aug 11, 2026

A critical firmware vulnerability in Coinkite's Coldcard hardware wallets, active since March 2021, allowed attackers to steal approximately $130 million in Bitcoin. The exploit of these offline devices triggered a mass migration of funds, driving weekly U.S. spot Bitcoin ETF inflows to over $850 million and pushing weekly new Bitcoin address creation from 260,000 to over 330,000. The incident has reignited intense debate over the security of self-custody versus institutional custodial solutions.

Coldcard firmware vulnerability

  • ▪A firmware bug shipped in March 2021 in Coinkite's Coldcard hardware wallets bypassed the device's hardware randomness chip, generating predictable seed phrases using a weak software random number generator.
  • ▪The Coinkite Coldcard firmware vulnerability remained undetected in public code for five years before being exploited in a series of thefts beginning in July 2026.
  • ▪Coinkite advised Coldcard users who generated wallets between March 2021 and the release of a security patch to migrate their funds to newly created wallets.

Bitcoin theft totals

  • ▪Attackers exploited the Coldcard firmware vulnerability to steal approximately $130 million in Bitcoin, representing about 2,000 tokens drained from over 5,200 addresses, according to Galaxy Research tracking.
  • ▪The Coldcard hardware wallet thefts occurred across four distinct waves starting on July 30, 2026, resulting in the loss of at least 1,816 Bitcoin.

Self-custody versus custodial debate

  • ▪The Coldcard exploit intensified debate over self-custody, with security researcher Jameson Lopp and developer Peter Todd defending self-custody, while others advocated for custodial options like exchange-traded funds.
  • ▪Onramp co-founder Michael Tanguma argued that both single-signature self-custody and centralized custodians present single points of failure, advocating instead for multi-institution multi-signature custody solutions.

Bitcoin ETF inflows surge

  • ▪According to Bitcoin Magazine, U.S. spot Bitcoin exchange-traded funds recorded $626 million in inflows in the days immediately following the Coldcard hardware wallet hack.
  • ▪U.S.-listed spot Bitcoin exchange-traded funds attracted over $850 million in weekly inflows following the Coldcard wallet exploit, marking their strongest weekly inflows since April 2026.

New Bitcoin address creation

  • ▪The sudden increase in new Bitcoin addresses in August 2026 sharply reversed a downward trend in network address creation that had persisted for most of the year.
  • ▪The number of new Bitcoin addresses climbed from roughly 260,000 to more than 330,000 during the week of the Coldcard exploit.

4 sources

Theblock
New Bitcoin addresses jump as Coldcard exploit pushes users to move funds
View source article
Forbes
After A $130 Million Hack, Bitcoin Asks Who Should Hold The Keys
View source article
Fortune
Why the latest Bitcoin hack hurt more than most | Fortune
View source article
Bloomberg
Bitcoin (BTC) ETF Inflows Hit $850 Million After Coldcard Wallet Hack
View source article

Story comments

Loading comments…

Related Projects

Bitcoin

Topics

Bitcoin wallets & custodyBitcoin security & risksHardware wallet vulnerabilitiesBitcoinCrypto security