Roughly 1,367 bitcoin, worth nearly $89 million, were drained from 4,585 Coldcard hardware wallet addresses starting July 30, 2026, according to on-chain analysis by Galaxy Research. The attacker never physically touched any device. The cause: a firmware bug introduced in March 2021 that made supposedly random private keys predictable enough to reconstruct from scratch.
Hardware wallets have long been sold as the gold standard of Bitcoin security. Offline, air-gapped, resistant to remote attack. Yet thousands of Coldcard devices were emptied in successive waves while their owners had no idea anything was wrong. Here's what actually happened, why Bitcoin itself isn't the problem, and whether you need to act right now.
🚨 A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained.
— Galaxy Research (@glxyresearch) August 1, 2026
Our estimated observed size of the Coldcard hack is now 1,367.05 BTC (~$88.6m) across 4,585 addresses.
More updates in the thread below 👇 https://t.co/hPtXh9444D pic.twitter.com/g6xA4OOi2f
What Happened: The Numbers Behind the Attack
Galaxy Research's blockchain analysis paints a stark picture. The first wave, hitting on July 30, drained approximately 594 bitcoin in under thirty minutes. Subsequent waves pushed the total to around 1,367 BTC, stripped from 4,585 separate addresses, for a combined loss approaching $89 million at the time of the theft.
Many of those wallets had been dormant for years. Their owners kept them in a drawer, confident their savings were locked away safely, only to find the balances zeroed out without having clicked a single link, opened a suspicious email, or made any mistake. The attacker needed no social engineering whatsoever, only the ability to exploit a predictable key-generation flaw.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW
, Alex Thorn (@intangiblecoins) August 3, 2026
THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS
pattern identified:
blocks…
The Cause: Randomness That Wasn't Random
The technical explanation matters here, so let's make it clear. A hardware wallet's entire security model depends on one thing: when you set it up, the device generates a secret seed by drawing from a pool of combinations so astronomically large that guessing it is practically impossible. That randomness has to be genuine and unpredictable. Everything else is built on top of it.
A firmware update pushed in March 2021 broke that foundation for certain Coldcard devices. Instead of using the device's dedicated hardware random number generator, affected units fell back on a software-based method that drew on non-secret chip data. The result was a dramatic collapse in the effective size of the keyspace. What should have been computationally impossible to brute-force became something a computer could systematically work through. Private keys that owners believed were uniquely theirs were, in fact, reconstructible by anyone who understood the flaw, no physical access required.
The Coldcard Attack: Key Facts
Source: Galaxy Research, Coinkite, 2026
- ~$89 million: approximately 1,367 bitcoin drained from 4,585 addresses in multiple waves from July 30, 2026.
- Root cause: a March 2021 firmware bug that made private keys predictable and reconstructible without device access.
- Who is safe: Bitcoin itself is unaffected. Newer Coldcard models (Mk4, Q, Mk5) are not impacted by this specific flaw.
Why Bitcoin Isn't Broken (But the Lesson Stands)
Let's be direct: this is not a Bitcoin vulnerability. The Bitcoin network and its underlying cryptography remain intact. No protocol-level code was exploited. What failed was a specific firmware version from a single manufacturer, in a specific window of time. Think of it like a safe manufacturer accidentally shipping a batch with a defective lock cylinder. The steel is fine, though the mechanism failed.
That said, the broader lesson for anyone holding crypto is uncomfortable. Security doesn't end at “keep your keys offline.” It starts with how those keys were generated in the first place. An air-gapped device is worthless if the key it produced was weak from day one. This is the same principle we explore in our guide to self-custody and wallet security: a security chain is only as strong as its weakest component.
Are You at Risk? A Practical Checklist
The exposure is specific and well-defined. Not every Coldcard owner is affected, and users of other hardware wallet brands are not involved in this particular attack. You are potentially at risk only if all of the following conditions apply at once.
, nvk (@nvk) July 31, 2026
- You own an older Coldcard model (Mk3 specifically).
- You generated your seed directly on the device while it was running the vulnerable firmware from that period.
- You did not add an additional passphrase on top of the seed.
If you have a newer model, imported a seed created on a different device, or added a passphrase, you are not exposed to this specific flaw. One critical warning, though: updating the firmware now will not save you if your seed was already generated with the bug. The patch prevents new seeds from being weak, but it cannot retroactively fix a key that was born compromised. The only real fix is to generate a fresh wallet on a clean, trusted device and move your funds there as a matter of urgency.
The Bigger Picture
The Coldcard incident is one of the most instructive security failures in years, precisely because it strikes at an assumption the crypto world treated as settled: that cold storage is an impenetrable fortress. It is still the most secure approach available. But only if every component in the chain is built correctly. A single bug, hidden in plain sight in open-source code for five years, was enough to turn a vault into an open door.
The takeaway for self-custody holders isn't “cold storage is dangerous.” It remains the safest method. The real lesson is that self-custody is a responsibility, not just a product purchase. It requires understanding how your keys were born, keeping firmware updated. Not concentrating everything in one device from one manufacturer. Blind trust in any hardware, however well-regarded, is itself a risk vector. In the world of Bitcoin security, the most durable protection isn't the hardware. It's the knowledge behind it. Anyone looking to build on these fundamentals can start with our guide on how to store crypto safely.


