Coldcard Firmware Exploit Leads to Theft of 2,100 BTC, Nearly $130M Loss

Coldcard Firmware Exploit Leads to Theft of 2,100 BTC, Nearly $130M Loss

N
News Editor
2026-08-12 18:22:54
According to a report from ChainCatcher, a firmware vulnerability in Coldcard hardware wallets has been exploited, leading to the theft of roughly 2,100 Bitcoin and causing losses that approach $130 million. Data from the blockchain indicates that in the days around the exploit, wallets associated with long-term holders sent out approximately 233,000 Bitcoin, worth around $15 billion. Nick Neuman, the chief executive officer of Casa, stated that a portion of these outgoing transfers came from Coldcard users who were moving their holdings into multisignature wallets. He also noted that users of Ledger and Trezor devices adopted similar measures after the security incident. During the same period, close to 22,000 Bitcoin were shifted into exchange platforms. In response, Coinkite, the company behind the Coldcard product line, has instructed customers who generated their mnemonic phrases using firmware versions 4.1 through 4.1.9 to regard their wallets as compromised and to migrate to new seed phrases without delay. These firmware versions correspond to the timeframe spanning March 2021 to July 2026.

Incident Overview

A firmware vulnerability in Coldcard hardware wallets was exploited, resulting in the theft of around 2,100 Bitcoin and losses approaching $130 million, according to ChainCatcher. Blockchain data from the days surrounding the event shows that wallets belonging to long-term holders sent out roughly 233,000 Bitcoin, worth approximately $15 billion.

Fund Movements and Industry Reaction

Nick Neuman, chief executive officer of Casa, said a portion of the transferred funds came from Coldcard users migrating to multisignature wallets. Neuman also said Ledger and Trezor users took similar measures following the incident. About 22,000 Bitcoin flowed into exchanges during the same period.

Coinkite Security Advisory

Coinkite, the manufacturer of Coldcard, has instructed anyone who generated a mnemonic phrase using firmware versions 4.1 to 4.1.9 to treat their wallet as compromised and to migrate to a new seed phrase immediately. Those versions were in use from March 2021 through July 2026, so wallets created over that span fall under the advisory.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
420

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.