Security researchers say a Coldcard wallet flaw helped attackers drain nearly $89 million in bitcoin from thousands of addresses in a matter of days.
Quick Take
- The first major sweep hit on July 30 and moved 1,082.65 bitcoin from 1,196 addresses in 41 minutes.
- Galaxy Research later said the total had grown to 1,367 bitcoin from 4,585 addresses across three waves.
- Reporting ties the problem to a Coldcard seed-generation flaw that dates back to a March 2021 firmware build.
- Coinkite warned users and pushed patched firmware while researchers tracked more possible follow-on activity.
How the Attack Unfolded
The story began as a fast, narrow theft and then widened into something much larger. Coindesk reported the opening wave on July 30, when roughly 1,083 bitcoin was swept from 1,196 addresses in 41 minutes. That alone made the incident stand out.
The pace was mechanical, the targeting was broad, and the wallets were not random picks. They were linked by the same weak seed process inside Coldcard devices.
By early August, Galaxy Research said the losses had climbed to 1,367 bitcoin, worth nearly $89 million, across 4,585 addresses. KuCoin and other reports said the flaw traced back to a March 2021 firmware build that affected how some Coldcard devices generated wallet seeds.
That matters because seed creation is the root of wallet security. If the seed is weak, the private key can be guessed offline without touching the device.
Why This Bug Was So Dangerous
Coldcard is known as a Bitcoin-only hardware wallet, which gives users a strong sense of control and distance from online threats. That reputation made the flaw sting harder.
Yahoo Finance reported that Block’s engineering team found some firmware could silently fall back to a weak, deterministic software random number generator instead of the hardware random number generator. In plain terms, the wallet was supposed to create a hard-to-predict seed, but sometimes it did not.
That kind of failure is especially dangerous because it does not need phishing, malware, or physical access. A thief who can predict the seed path can reconstruct the key from outside the wallet.
Crypto.news and Coinkite-related reporting said the bug reduced the effective randomness in affected seeds and exposed certain Coldcard models and firmware ranges released after March 2021. Once that happens, the air gap does not matter nearly as much as users expect.
What Researchers Saw On Chain
The on-chain picture made the case hard to ignore. CoinDesk said the first sweep moved the funds across 500 transactions inside a three-block window, and later consolidation pointed to organized control of the stolen coins.
Infosecurity Magazine reported that Galaxy researchers treated the activity as likely automated and said the first wave drained funds from nearly 1,200 addresses. That scale suggests the attacker did not stumble onto one lucky wallet. The operation looked planned, fast, and repeated.
Coldcard Wallet Hack Drains Over 1,367 $BTC Worth ~$86 Million
Hackers have exploited a software vulnerability in Coldcard, one of the most trusted Bitcoin hardware wallets, stealing approximately 1,367 $BTC (worth around $86 million) from more than 4,500 wallets, according to… https://t.co/tzzYWcTyu4
— GUL (@gulVasikova) August 3, 2026
The later waves pushed the incident from a bad day for users into a broader warning for the entire self-custody market. Fox Business said researchers initially framed the attack as roughly $70 million, then updated the estimate as more waves appeared. That is common in live security incidents.
The first count is often the smallest one, because later blockchain traces reveal more victims. In this case, the number kept climbing because the theft apparently was not finished.
What Coldcard Users Faced Next
Coinkite issued a security warning after the first wave and told users that seeds created on affected firmware could be at risk. Reports said the company also released patched firmware by August 1.
For users, the lesson was blunt. Hardware wallets reduce online risk, but they do not forgive a bad seed generator. If the random number step fails, the wallet can still fail in a way that feels impossible until the coins are gone.
The larger lesson reaches beyond one brand. Crypto storage tools often earn trust because they look simple and isolated. This case shows that the hidden parts matter most. A tiny firmware mistake can turn a premium security product into a predictable target.
That is why seed generation, firmware updates, and careful setup are not side issues. They are the whole game when the asset is bitcoin and the attacker can work from the chain itself.
Sources:
foxbusiness.com, thehackernews.com, coindesk.com, techspot.com, cryptopolitan.com, finance.yahoo.com, reddit.com





























