Coldcard Hack in 2026 Sparks $116M Loss and 210,000 BTC Movement

iconIncrypted
Share
AI summary iconSummary
A Coldcard hardware wallet hack in late July 2026 caused a $116 million loss, with 210,000 BTC moved from long-term holders. TRM Labs labeled it the third-largest crypto hack of 2026, tied to a firmware flaw dating to March 2021. The vulnerability enabled brute-force attacks on seed phrases, leading to 1,816 BTC stolen from over 5,200 addresses. Glassnode noted this BTC movement marked the largest drawdown since December 2024. Chainalysis found Canadian users accounted for 25% of losses, with major impacts in Australia, the U.S., and Thailand. The incident raises questions about BTC price stability and BTC dominance amid growing security concerns.
  • After the Coldcard hack, long-term holders moved 210,000 BTC.
  • The wallet attack was one of the biggest in 2026.
  • A five-year-old mistake cost bitcoin holders at least $116 million.

After a major hack of Coldcard hardware wallets in late July 2026, the Bitcoin network saw unprecedented activity from long-term holders. According to Glassnode, over the past week about 210,000 BTC was moved from wallets that had not moved funds for at least 155 days.

Against this backdrop, TRM Labs estimated losses from the year’s third-largest hack at $116 million, Chainalysis reported significant losses among Canadian users, and researchers stress that this is more about a mass migration of assets to new addresses than panic selling.

Incrypted infographic.

The Coldcard Hack Triggered the Biggest Move of “Old” Bitcoin Since 2024

Glassnode analysts reported that over the past week, long-term holders (LTH) moved roughly 210,000 BTC.

This is the largest drawdown in holdings for this investor cohort since December 2024, when bitcoin first approached the $100,000 mark.

The total supply held by long-term bitcoin holders over the past year. Source: Glassnode.

At Glassnode, long-term holders are defined as addresses whose coins have remained unmoved for at least 155 days. This cohort is traditionally seen as “smart money,” as it typically ignores short-term volatility.

Before the Coldcard incident, they controlled nearly 15 million BTC. After the coins were moved, that figure fell to roughly 14.7 million BTC.

Unlike previous cycles, this time the mass movement of coins did not occur at all-time highs, CoinDesk noted.

Historically, large LTH transfers were observed near market tops — in March 2021, March 2024, and December 2024 — when seasoned investors took profits.

The situation is different now: bitcoin is trading near $64,000, according to TradingView — about 50% below the all-time high from October 2025. That is why analysts believe most of the transfers are linked not to selling, but to a change in where assets are stored after a critical vulnerability was discovered.

A Five-Year-Old Bug Led to One of the Year’s Biggest Hacks

According to TRM Labs, the attack on Coldcard was the third-largest crypto hack of 2026.

According to the company, starting on July 30, attackers stole about 1,816 BTC (around $116 million) from more than 5,200 addresses across four separate waves of attacks. At the same time, Galaxy Research estimated roughly 2,055 BTC, or nearly $130 million, in potential losses.

The cause was a firmware bug dating back to March 2021.

Due to an incorrect configuration during the software build process, seed phrase generation partially relied on a software pseudorandom number generator instead of the hardware random number generator. As a result, the cryptographic strength of the keys could drop from 128 bits to about 40 bits on older devices, making it possible to brute-force them without physical access to the wallet.

Lookonchain reported that the hacker continues to move the stolen funds. According to the latest data, they transferred another 30.185 BTC (nearly $1.94 million) to a new address.

TRM noted that, for now, the stolen funds are mostly concentrated across a handful of attacker-controlled addresses.

According to the researchers, so far they have recorded only one deposit into Wasabi Wallet and one into Tornado Cash, meaning large-scale laundering has not yet taken place.

At the same time, the transaction structure across different attack waves points to the possible involvement of several independent hackers.

“Transaction patterns suggest multiple attackers may be involved, so TRM isn’t attributing the theft to a specific actor yet,” TRM Labs said.

Coinkite Explained the Cause of the Vulnerability, and Experts Are Helping Victims

After the incident drew widespread attention, Coinkite published a technical explanation and stressed that the common phrasing about a “weak fallback random number generator” is inaccurate.

According to the developers, the weak Yasmarang generator was not a dedicated Coldcard fallback system, but has been part of MicroPython’s standard library since 2018.

The original design called for using only a hardware true random number generator (TRNG), but due to an error during the software build process, the system unexpectedly began using the runtime’s implementation instead.

“What people are describing as a “fallback” wasn’t an intentional design decision or a shortcut in the seed-generation logic—it was inherited behavior from the underlying platform that became active because of a link-time error,” Coinkite explained.

The company separately emphasized that the firmware update does not protect wallets that have already been created.

All users who generated seed phrases on Coldcard after March 2021 and before the fix was released must create a new wallet and transfer funds to a new seed phrase.

Researchers Call the Attack a Tragedy for the Bitcoin Community

James Thorne, head of research at Galaxy Digital, told Bloomberg that he has already spoken with more than 100 affected users.

He is coordinating the collection of information about victims, analyzing the movement of the stolen bitcoin, and passing materials to law enforcement.

According to him, many victims lost all of their savings.

“These are average everyday people saving their money in Bitcoin. They were true believers.”

The researcher also added that some victims told him they were in a severe psychological state.

Canada Suffered the Biggest Losses, and Ledger Compared the Incident to Trust Wallet

According to Chainalysis estimates, users from Canada were hit hardest by the hack.

Canadian bitcoin holders account for about 25% of all confirmed losses. Significant losses were also recorded in Australia, the United States, and Thailand.

Charles Guillemet, Ledger CTO, compared the incident to the well-known 2023 Trust Wallet vulnerability.

According to him, the issue once again showed that randomness in seed phrase generation is a fundamental cornerstone of crypto wallet security.

“Every private key you own derives from one number: the seed. If that number is predictable, everything derived from it is too.”

Separately, researchers also drew attention to the privacy implications for the Bitcoin network.

In particular, an X user under the handle Cole noted that compromising seed phrases allows attackers to reconstruct the full transaction history of affected wallets even after funds are moved.

According to him, this also makes things easier for blockchain analytics firms, as they can more accurately cluster addresses belonging to the same owner.

Meanwhile, the well-known blockchain investigator ZachXBT said he does not plan to join the investigation into this incident.

As a reminder, experts found a record level of negative sentiment around the first cryptocurrency following the Coldcard exploit.

Сообщение One of the Biggest 2026 Wallet Hacks of Coldcard Changed Bitcoin Investors’ Behavior появились сначала на INCRYPTED.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.