Coldcard exploit grows into largest Bitcoin theft of the year as stolen total reaches 1,359 BTC
Coldcard’s security incident has developed into what BlockBeats described as the largest Bitcoin theft of the year, with the stolen total reaching 1,359 BTC. The reported flaw was tied to firmware code released in March 2021, while the vulnerable logic is said to have existed in open-source code for more than five years. Affected devices included the Mk3, some Mk2 units, and seed generation on the Mk4, Q, and Mk5 before a fix was applied. The large-scale exploitation was carried out on July 30, 2026, with attackers sweeping hundreds to more than a thousand addresses in roughly 25 to 41 minutes. Coinkite later acknowledged a seed-generation issue affecting Mk3 firmware 4.0.1 and later, and said the attacker may have used AI to review open-source code. Galaxy’s Alex Thorn said smaller attackers and copycats are now targeting remaining Coldcard mnemonic phrases, while BitGo CEO Mike Belshe responded by depositing 100 BTC to a public address and inviting Anthropic’s Claude to try to move the funds.




