Coldcard Wallet Hack: 1,359 BTC Stolen in the Largest Bitcoin Theft of 2026

iconKuCoinFlash
Share
AI summary iconSummary
A major security breach in Coldcard hardware wallets has resulted in the theft of 1,359 BTC, marking the largest Bitcoin theft of 2026. The vulnerability, present in firmware code from March 2021, enabled attackers to drain high-balance addresses in under 41 minutes. Coinkite confirmed the issue and warned users to exercise caution when moving BTC. Galaxy’s Alex Thorn stated the attack is spreading, with more imitators emerging. CZ highlighted the risks of self-custody, emphasizing that older Coldcard wallets remain vulnerable. BitGo CEO Mike Belshe tested his platform’s security by depositing 100 BTC into a public address. BTC dominance faced slight pressure as Bitcoin’s price declined from $65,000 to $63,000.

BlockBeats report, August 3: Latest data shows that 1,359 bitcoins have been stolen in the Coldcard hardware wallet hacking incident. Additionally, users have reported issues such as devices getting stuck on error pages, failing to boot, or appearing bricked after installing updates. This incident has become the largest bitcoin theft of the year. BlockBeats has compiled the timeline of events as follows:


Analysis shows that the compromised Coldcard firmware code was released in March 2021; the vulnerability existed in the open-source code for over five years and affected seed generation on Mk3 (and some Mk2), as well as subsequent Mk4, Q, and Mk5 models prior to the fix.


Large-scale attacks exploiting this vulnerability were carried out until July 30, 2026. Over a period of approximately 25–41 minutes, attackers automated sweeps targeting hundreds to thousands of addresses. Initially, around 500 single-signature wallets and 1,324 UTXOs, totaling approximately 594.5 BTC, were compromised; subsequent on-chain analysis expanded the scope to about 1,196 addresses and 1,082.65 BTC (valued at approximately $70.2 million). Additionally, the attack prioritized addresses with larger balances, employed fixed high fees, and produced no change outputs, rapidly consolidating funds into a small number of addresses.


Subsequently, Coinkite, the developer of Coldcard, released a security advisory confirming initially that the seed generation issue affects Mk3 (firmware 4.0.1 and later), advising affected users to migrate cautiously, and speculating that attackers may have used AI to review open-source code to identify the vulnerability.


As of August 2, Galaxy research lead Alex Thorn stated that the attacks surrounding the Coldcard wallet are still evolving, with more small-scale attackers and imitators emerging to target remaining Coldcard mnemonic phrases.


This incident has drawn attention from multiple parties. Eric Balchunas, Senior ETF Analyst at Bloomberg, revealed that the Coldcard team consists of only five employees—a surprisingly low number for such an important company.


CZ commented, "In a self-custody model, even if developers patch the vulnerability, they cannot fix wallets that were already generated; for users employing isolated devices, developers cannot directly contact or alert them. Until users take proactive action, affected wallets may remain exposed to attack risks. I support self-custody, but this also means users bear full responsibility for their own security."


Additionally, since the incident may involve AI compromising cryptographic devices, institutional custody platform BitGo took the first action to help restore the industry’s reputation. On August 1, BitGo CEO Mike Belshe deposited 100 BTC into a publicly accessible Bitcoin address and invited Anthropic’s Claude model to attempt to transfer the funds. The platform employs multi-signature or multi-party computation technology to distribute signing authority across multiple independent keys. As of August 2, Anthropic had not publicly responded to this challenge.


Affected by this, Bitcoin has remained weak since the 31st, dropping from $65,000 to $63,000.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.