Coldcard Wallet Hack Exposes 5-Year-Old Flaw, Drains $114M in Bitcoin

iconCryptoBriefing
Share
AI summary iconSummary
Bitcoin news broke as hackers exploited a Coldcard wallet flaw, draining 1,816 BTC ($114M) from over 5,200 addresses. The vulnerability, present since 2021, reduced seed randomness to 40 bits. Galaxy Research called the attack systematic, not isolated. Coinkite is analyzing the breach but hasn’t confirmed losses. Bitcoin analysis suggests this could push investors toward regulated products.

The hardware wallet industry built its reputation on a simple promise: keep your Bitcoin offline and keep it safe. That promise took a serious hit on July 30, 2026, when attackers began exploiting a vulnerability in Coinkite’s Coldcard hardware wallets, ultimately draining what revised estimates place at 1,816 BTC, roughly $114 million, from more than 5,200 addresses. Some estimates suggest total losses could climb past $130 million as sweep activity continues.

The vulnerability traces back to firmware version 4.0.1, released by Coinkite in March 2021. The flaw compromised the randomness used when generating wallet seeds, which are the master keys from which all private keys in a Bitcoin wallet are derived. Key strength, which ideally sits at 128 bits of entropy, dropped as low as 40 bits in affected devices. At 40 bits, brute-force attacks become computationally feasible with modern hardware.

Advertisement

By early August, Galaxy Research estimated losses at approximately 1,367 BTC across 4,585 addresses. As attackers continued sweeping vulnerable wallets in subsequent waves, that figure climbed to 1,816 BTC implicated across more than 5,200 addresses. The progression matters because it signals the exploit was not a one-time smash-and-grab but a systematic, ongoing operation targeting every wallet seeded with the flawed firmware.

Coinkite has not released a specific loss estimate. The company has indicated it is conducting a post-mortem analysis before commenting on the full scope of device compromise and user impact.

The irony is that this exploit required no internet connection to succeed. The vulnerability lived in the firmware’s key generation logic. Any wallet seeded using a compromised version of that firmware was vulnerable from the moment it was created, regardless of how carefully the owner protected the physical device afterward.

Galaxy Research analysts suggest the exploit could accelerate a shift toward regulated Bitcoin investment vehicles. ETF providers rely on institutional custodians operating under regulatory oversight, with insurance frameworks and security audits that individual hardware wallet users cannot replicate.

For investors currently holding Bitcoin on any hardware wallet, the immediate priority is verification. If a device was seeded using Coldcard firmware version 4.0.1, funds should be transferred to a wallet generated on a different, verified device as a precautionary measure. Waiting for Coinkite’s official post-mortem before acting is a risk calculation that many holders may not want to make while active sweeping continues.

Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.