Coldcard flaw tied to theft of about 1,366 BTC, reigniting debate over self-custody

Coldcard flaw tied to theft of about 1,366 BTC, reigniting debate over self-custody

N
News Editor
2026-08-03 13:58:54
A long-running firmware flaw in Coldcard hardware wallets has been linked to one of the biggest Bitcoin thefts of the year, with roughly 1,366 BTC stolen as of Aug. 3, according to the Coldcard Sweep Watch dashboard. The bug, traced to a code migration in March 2021, caused affected devices to fall back from a hardware true random number generator to a weaker software pseudo-random scheme when creating wallet seeds. That made some seeds predictable enough to be brute-forced offline, allowing attackers to derive wallet addresses and drain funds without touching the device, sending phishing links, or installing malware. Galaxy Research said the campaign unfolded in three waves on July 30, July 31 and Aug. 1, with a suspected fourth wave still underway. The firm also said the first attack started about 30 hours before Coldcard’s public warning. Coinkite said users who added at least 50 private dice rolls during seed generation or used a strong passphrase faced much lower risk, and that Satscard, Opendime and Tapsigner were not affected. The incident has since spilled into broader market and custody discussions, with on-chain transfer activity rising, Bitcoin slipping from around $65,000 to near $63,000, and industry figures split over whether self-custody, multisig setups, ETFs or institutional custody now offer the safer path.
ColdcardCoinkiteBitcoinhardware walletself-custodysecurity漏洞Galaxy Research

A firmware flaw in Coinkite’s Coldcard hardware wallets has been tied to a large-scale Bitcoin theft that disrupted the market at the end of July.

Attackers did not need physical access to the device, phishing links, or malicious software installed by users. They were able to move funds remotely. Many of the affected addresses had been dormant for years, and some owners had never connected their devices to the internet.

According to the Coldcard Sweep Watch dashboard, the amount stolen had climbed to about 1,366 BTC as of Aug. 3, worth close to $90 million. That made it the largest Bitcoin theft of the year cited in the report. A suspected fourth wave of attacks was also still in progress, pushing the tally higher.

The flaw came from seed generation

When a user creates a wallet on Coldcard, the device generates a random seed. All private keys and addresses are derived from it. If that seed is not random enough and can be predicted, the wallet’s protection breaks down.

Hardware wallets usually rely on a dedicated true random number generator chip that uses physical noise to produce values that cannot be guessed. In this case, the failure happened at exactly that point.

According to an incident report from Block Engineering, a mistaken condition introduced during a code migration in March 2021 caused the firmware to stop properly calling the hardware random chip when generating seeds. Instead, the device silently fell back to a software pseudo-random scheme. Its initial inputs included chip serial numbers, timer readings and other values that were public or inferable.

That changed the nature of the seed. Rather than being effectively unpredictable, it became something an attacker could work backward from using a fixed process. By reproducing that logic, an attacker could enumerate a large set of possible seeds offline, derive the corresponding addresses, compare them with public on-chain addresses, and once a match was found, spend the coins as if they held the private key.

Coinkite estimated that the hardest-hit Mk3 model saw its effective randomness collapse from an intended 128 bits to about 40 bits. The Mk4, Mk5 and Q models mixed in some additional entropy from a secure element and ended up at roughly 72 bits. Both levels were described as far below what is needed for safety, and the report said modern computing power is sufficient to brute-force them.

The flaw had been present in public firmware code since March 2021, spanning multiple versions, and did not surface in a major way until it was exploited at scale on July 30, 2026.

Not every Coldcard user faced the same level of exposure. Coinkite said risk was sharply reduced for users who added at least 50 independent private dice rolls during seed generation or used a sufficiently strong passphrase. The company also said its Satscard, Opendime and Tapsigner products were unaffected because they run on different codebases.

Three attack waves identified, with a fourth suspected

Galaxy Research said the theft campaign unfolded in three waves.

  • The first wave hit on July 30, when 1,195 addresses were completely drained and about 1,082.65 BTC was stolen.
  • The second wave followed on July 31 and involved 1,478 addresses.
  • The third wave came on Aug. 1 and involved 1,912 addresses.

Galaxy Research said the first wave started about 30 hours before Coldcard issued its public warning. In practice, that meant many users had already lost funds before they saw any alert.

A suspected fourth wave is now underway, with preliminary estimates putting the amount at about 449 BTC, and losses are still rising.

On-chain movement, price pressure and recovery efforts

The incident quickly spread beyond the compromised wallets and into on-chain activity and market behavior.

After the collapse of FTX in 2022, investors withdrew large amounts of Bitcoin from exchanges and shifted toward self-custody, including hardware wallets. This time, the report said, Bitcoin appears to be moving back toward exchanges.

Julio Moreno, head of research at CryptoQuant, disclosed data showing that the number of on-chain transfers below 1 BTC rose to its highest level since November 2022. Around 39,600 BTC moved in a single day, only about 300 BTC below the record set in the days after FTX filed for bankruptcy.

Bitcoin also weakened in price from July 31, falling from around $65,000 to near $63,000.

Galaxy Research also highlighted several details about where the stolen coins went and whether they can still be recovered. Its tracking suggests almost all of the stolen Bitcoin remains parked at addresses controlled by the attackers and has not yet entered exchanges or mixing services. That is why a recovery window may still exist.

The attack pattern, however, is changing. In the first two waves, funds were consolidated into a small number of addresses, which left a clearer on-chain trail. In the third wave, the attackers switched to 293 one-to-one transfer routes. Each drained wallet was paired with a fresh destination address, with no shared consolidation point, making detection harder.

During efforts to trace and freeze funds, Galaxy Research head Alex Thorn said one victim who held nearly 30 BTC saw 17 BTC swapped across chains into ETH and then deposited to the entertainment platform Duel. The victim emailed the platform requesting a freeze, but the funds were moved out before that could happen.

Thorn also said the Coldcard attack was still active and that more small attackers and copycats had emerged, targeting the remaining pool of vulnerable Coldcard mnemonic phrases.

Coinkite response and user complaints

Coinkite said the previous three days had been among the hardest in the company’s history. The team said it had been contacting customers since last Friday and helping move funds that were still safe.

The company said it had destroyed remaining inventory produced with the vulnerable firmware and paused shipments. It also warned that updating firmware does not repair old seeds that were already generated. Affected users need to create a new wallet and transfer their funds.

Even so, some users said their devices became stuck on an error screen after the update, would not boot, or appeared to be bricked. The complaints were said to mainly involve Mk4 and Q devices.

Self-custody comes under pressure again

The incident has shaken confidence in self-custody.

Binance founder Changpeng Zhao said that in a self-custody model, developers can fix the bug going forward but cannot repair wallets that were already created. For users operating isolated devices, developers also cannot directly reach them with warnings. Until the user takes action, those wallets may remain exposed. Zhao said he supports self-custody, but added that it also means the user bears the security burden.

Bloomberg ETF analyst Eric Balchunas approached the issue from team size. He said Coldcard has only about five employees, which he argued is too few for a company of such importance, and asked whether users would want to place their life savings with a company of that size. In his view, larger institutions may have more resources to spend on security, and Bitcoin ETFs offer another option.

AI code review enters the picture

The spread of AI tools added another layer to the incident.

One developer said Claude Code found the core issue in Coldcard’s open-source firmware in about eight minutes. Community users also said Zhipu GLM 5.2 independently identified the same flaw during code scanning.

Coinkite, for its part, said it had used what it described as top AI models a few weeks earlier to review the code and did not find the issue. The company said it suspects the attackers may have used AI to review older open-source firmware.

On Aug. 1, in what the report described as a possible effort to restore confidence in the sector, Bitgo CEO Mike Belshe sent 100 BTC to a public Bitcoin address and invited Anthropic’s Claude model to try to move the funds from that address.

Hardware wallets, institutional custody and the next standard

Strive Vice President Joe Burnett said this may be one of the worst stretches in Bitcoin’s history. People bought widely accepted hardware wallets, generated mnemonic phrases offline, and followed established best practices, yet still suffered heavy losses because of this flaw.

He said the event will change how people view self-custody. Self-custody will not disappear, but for those who want direct control over large Bitcoin holdings, the standard should move to multi-vendor multisig. Users unwilling to accept that level of complexity, he said, should use institutional-grade custody.

Hardware wallet security failures are not unprecedented. But in many earlier cases, attacks required physical access to the device or tampering somewhere in the supply chain, which raised the barrier and limited scale. This case was different: it was purely software-based, remote, and capable of being automated in bulk.

Institutional custody, however, carries a different set of concerns. Critics argue that it can concentrate too much Bitcoin in large companies and create risks around censorship, seizure and confiscation.

The result is a familiar dilemma with no settled answer. The question of where self-custody goes from here is now being re-examined by more of the market.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.