A five-year-old firmware defect in Coinkite's Coldcard hardware wallet has been exploited to steal at least 1,816 BTC — approximately $117 million at current prices — from more than 5,200 addresses across four coordinated attack waves beginning July 30, 2026. The vulnerability, introduced in a Ma...
"I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news." — Rodolfo Novak (NVK), CEO, Coinkite
A five-year-old firmware defect in Coinkite's Coldcard hardware wallet has been exploited to steal at least 1,816 BTC — approximately $117 million at current prices — from more than 5,200 addresses across four coordinated attack waves beginning July 30, 2026. The vulnerability, introduced in a March 2021 firmware build, routed seed generation through a predictable software pseudo-random number generator (PRNG) instead of the device's hardware true random number generator (TRNG), reducing effective entropy on Mk2/Mk3 models to approximately 40 bits — far below the 128-bit minimum required by BIP-39.
Galaxy Research identified the attack pattern and tracked each wave in near-real-time. The incident has triggered a measurable reversal in Bitcoin self-custody trends: exchange-held BTC rose from 2.704 million to 2.715 million in the days following the exploit, with sub-1 BTC transfers to exchanges reaching 39,600 BTC in a single day — levels not seen since the FTX bankruptcy in November 2022. Bitcoin fell to $62,560 as sentiment deteriorated.
The exploit did not compromise Bitcoin's cryptographic foundations. It exploited a manufacturing-layer software error in one vendor's firmware — a distinction that matters technically but has done little to prevent a broader crisis of confidence in single-device self-custody.
The root cause was a build-configuration error in Coldcard firmware. A safety check verified whether a configuration macro for the hardware RNG was defined rather than whether it was enabled. The check passed silently, and seed generation fell back to a software PRNG seeded from the chip's serial number and timer registers — values an attacker can reconstruct or narrow down computationally.
The flaw affected firmware versions 4.0.1 through 4.1.9 on Mk3 devices, with broader versions 4.0.0 through 5.0.3 also implicated according to some analyses. The result: instead of drawing from the hardware TRNG's full entropy pool, affected devices generated wallet seeds with roughly 40 bits of effective randomness on Mk2/Mk3 models. Mk4, Mk5, and Coldcard Q models were partially affected, with Block's security team independently assessing their effective entropy at approximately 32 to 72 bits — still well below the 128-bit standard.
For context, 40 bits of entropy means approximately 1.1 trillion possible seeds. With modern GPU clusters or ASICs, brute-forcing this space is computationally feasible within days or weeks. The vulnerability persisted in production devices for over five years before exploitation.
Coinkite's own assessment suggests the flaw was likely discovered through AI-assisted code review. CEO Rodolfo Novak called the incident "a sober reality of the new AI paradigm," noting that automated tools can now identify latent firmware bugs faster than experienced security auditors.
Wave 1 — July 30, 2026: The initial and largest sweep drained approximately 1,083 BTC from 1,196 addresses in 41 minutes. The average loss per victim was roughly 1 BTC. This wave occurred approximately 30 hours before Coinkite publicly disclosed the flaw, according to reporting from CoinDesk.
Wave 2 — July 31, 2026: A second, smaller wave targeted additional addresses. Precise figures for this wave were not separately broken out in Galaxy Research's public reporting, but cumulative losses rose to approximately 1,160 BTC.
Wave 3 — August 1-2, 2026: The third wave swept 208 BTC from 1,912 addresses, with average losses dropping to approximately 0.1 BTC per victim. Galaxy Research noted operational changes: the attacker used transaction batching and pay-to-witness-script-hash (P2WSH) outputs enabling multisignature or timelock conditions. The shift in technique suggested either the original operator adapting their methods or a second attacker exploiting the same vulnerability. Cumulative losses reached 1,367 BTC ($88.6 million) across 4,585 addresses.
Wave 4 — August 3, 2026: Galaxy Research head Alex Thorn flagged a probable fourth wave in real-time on X. This wave moved 388.93 BTC across 218 transactions from 462 vulnerable addresses into 216 destination addresses. Unlike previous waves, which were analyzed retroactively, wave 4 was called out while affected users still had a technical route to save their coins. Cumulative losses rose to 1,815.75 BTC from 5,294 addresses.
The declining average loss per address across successive waves — from ~1 BTC in wave 1 to ~0.84 BTC in wave 4 — suggests the most profitable key space is being exhausted. However, Galaxy Research warned that additional waves remain likely as long as unpatched seeds hold funds.
Galaxy Research assessed each wave was "likely conducted by a single operator," though blockchain analysis alone cannot confirm whether the same entity orchestrated all four campaigns. Key forensic observations:
The attacker scanned only default BIP-44 derivation paths rather than multiple branches, indicating a brute-force enumeration of the constrained seed space rather than a targeted attack on specific users.
| Model | Firmware Versions | Effective Entropy | Status | |-------|------------------|-------------------|--------| | Mk2 | 4.0.0–4.1.9 | ~40 bits | Directly vulnerable | | Mk3 | 4.0.1–4.1.9 | ~40 bits | Directly vulnerable | | Mk4 | Various pre-5.6.0 | ~32–72 bits | Partially affected | | Mk5 | Various pre-5.6.0 | ~32–72 bits | Partially affected | | Coldcard Q | Pre-1.5.0Q | ~32–72 bits | Partially affected |
Coinkite's other products — TAPSIGNER, OPENDIME, and SATSCARD — use different firmware and are unaffected. Fixed firmware versions: 4.2.0+ (Mk3), 5.6.0+ (Mk4/Mk5), and 1.5.0Q+ (Coldcard Q).
Critically, updating firmware does not retroactively secure previously generated seeds. Users must generate entirely new seeds on patched firmware and transfer all funds to new addresses.
Coinkite CEO Rodolfo Novak issued a public apology on July 31, stating the company "accepted full responsibility for the firmware failure." His message to affected users: "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further."
The company released emergency firmware patches for all affected model lines within two days of the first attack wave. Coinkite also noted that its firmware code "has always been publicly viewable" — an open-source philosophy that, in this case, may have enabled the attacker to identify the flaw.
Coinkite cautioned against rushed migrations, warning that "rushing a wallet migration can create a more immediate risk than the issue you are trying to address." The company pledged to publish a full technical post-mortem and assist affected users with police reports, insurance claims, and independent investigations.
For users who must continue using affected hardware, Coinkite recommended supplementing device entropy with 50+ physical die rolls during seed setup and implementing separate BIP-39 passphrases.
The exploit weighed on Bitcoin's price and triggered measurable shifts in on-chain behavior:
The market reaction reflects the symbolic weight of the incident more than its absolute scale. At $117 million, the Coldcard exploit is modest compared to the $1.1 billion stolen across the crypto industry in H1 2026. But the target — air-gapped cold storage marketed as the most secure custody method — carries outsized significance for Bitcoin's self-sovereignty narrative.
The exploit exposed a specific failure mode: single-device, single-signature self-custody with factory-default entropy. It did not invalidate hardware wallets as a category, nor did it compromise Bitcoin's underlying cryptography.
However, the incident produced several structural consequences:
Multisig adoption pressure: Multisignature wallets were unaffected. The incident provides empirical evidence for the security advantage of requiring multiple independent signing devices from different vendors.
Entropy verification demand: Users who supplemented their device's entropy with independent sources (die rolls, coin flips) or used strong BIP-39 passphrases were protected. The exploit is likely to drive demand for verifiable entropy tools and user-controlled randomness in seed generation.
Flight to institutional custody: The net exchange inflow of 11,163 BTC and the spike in small-holder transfers suggest some users view centralized exchanges and ETFs as the lower-risk option — a reversal of the post-FTX "not your keys, not your coins" trend.
AI-assisted vulnerability discovery: Coinkite's assessment that the flaw was likely found via AI code review raises questions about the expanding attack surface for open-source firmware. Latent bugs that survived years of human audit may now be discoverable in hours.
Rival hardware wallet manufacturers moved quickly to differentiate:
Ledger published a blog post titled "The Coldcard Incident: How Did This Happen?" stating that its devices use a certified hardware TRNG that generates "full 256 bits of entropy" per recovery phrase.
Trezor stated that its devices mix "multiple independent sources of randomness" rather than relying on a single implementation, reducing the risk of a single-point entropy failure.
Both companies emphasized their devices were unaffected. ELLIPAL published a technical explainer on the RNG vulnerability for its user base.
The Coldcard exploit is not a Bitcoin failure. It is a firmware quality-control failure at a single manufacturer that persisted undetected for five years. The distinction matters technically — Bitcoin's elliptic curve cryptography, SHA-256, and BIP-39 standard all performed as designed. The vulnerability existed entirely in the implementation layer: how one device generated the randomness that feeds into those otherwise sound cryptographic systems.
But the market is not making that distinction. The sight of air-gapped cold wallets being emptied remotely — the one thing hardware wallets were supposed to prevent — has damaged confidence in single-device self-custody. The 11,163 BTC net flow back to exchanges, the single-day spike in small-holder transfers to centralized platforms, and the price decline all indicate that some portion of Bitcoin holders have, at least temporarily, decided that the counterparty risk of an exchange is preferable to the implementation risk of self-custody.
The long-term question is whether this incident accelerates the adoption of multisignature custody, verifiable entropy, and multi-vendor setups — or whether it simply pushes more Bitcoin into centralized custodians and ETFs. The data from the next 90 days of on-chain flows will provide the answer.