A five-year-old firmware defect in Coinkite's Coldcard hardware wallet has resulted in the theft of approximately 1,816 BTC — roughly $116 million — from more than 5,200 addresses across four attack waves beginning July 30, 2026. The exploit, which reduced seed-generation entropy from 128 bits to...
"We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust." — Rodolfo Novak, CEO, Coinkite
A five-year-old firmware defect in Coinkite's Coldcard hardware wallet has resulted in the theft of approximately 1,816 BTC — roughly $116 million — from more than 5,200 addresses across four attack waves beginning July 30, 2026. The exploit, which reduced seed-generation entropy from 128 bits to as few as 40 bits, allowed attackers to brute-force private keys without physical access to devices. It is the largest hardware wallet exploit on record.
The incident has triggered a measurable behavioral shift in Bitcoin's holder base. Glassnode data shows 210,000 BTC leaving long-term holder wallets in the week following disclosure — the largest weekly decline in long-held supply since December 2024. Spot Bitcoin ETFs absorbed $620 million in daily inflows during the same period. The event has reopened fundamental questions about the distribution of custodial risk in digital asset storage and the economic viability of hardware-based self-custody as a mass-market solution.
The root cause traces to a single commit on March 1, 2021, in firmware version 4.0.1 for the Coldcard Mk3 product line. The change rerouted the seed-generation function from the STM32 chip's hardware random number generator (HRNG) to a deterministic software pseudorandom number generator called Yasmarang.
The mechanism was a C preprocessor error. Coinkite's MicroPython build disabled the platform's built-in RNG by setting MICROPY_HW_ENABLE_RNG to zero. The underlying library checked whether the flag was defined, not whether it was non-zero. A flag set to zero is still "defined" in C. The build silently compiled against the fallback code path, and the Yasmarang PRNG — initialized only from the chip's unique ID and timer registers — produced all subsequent seed entropy.
According to Coinkite's own technical backgrounder, effective entropy on affected devices collapsed to approximately 40 bits, against a design target of 128 bits. For context, a 40-bit keyspace contains roughly 1.1 trillion possibilities. Modern GPUs can exhaust that space in hours. All Coldcard Mk2 and Mk3 devices running firmware versions 4.0.1 through 4.1.9 are affected. The Mk4 and Q1 product lines, which use a different chip architecture, are not impacted.
Coinkite noted one mitigating factor: users who employed the "Add Dice Rolls" feature — entering at least 50 independent die rolls during seed generation — contributed at least 128 bits of external entropy, which was hashed together with the device-generated seed. Those seeds are not considered at risk from this flaw alone.
Galaxy Research tracked four distinct waves of exploitation:
Wave 1 — July 30, 2026: An attacker drained 1,082.65 BTC ($70.2 million at the time) from 1,196 addresses in a 41-minute window. Galaxy characterized the operation as "likely automated," with funds consolidating into four attacker-controlled addresses.
Wave 2 — August 1, 2026: A second sweep added approximately 285 BTC to the total, bringing the cumulative theft to roughly 1,367 BTC ($88.6 million) across 4,385 victim addresses.
Wave 3 — August 1-2, 2026: Galaxy cautioned that Wave 3 "should not be assumed to involve the same attacker," citing divergent transaction patterns from the first two waves.
Wave 4 — August 4, 2026: A fourth wave pushed the total to approximately 1,816 BTC ($116 million) from 5,294 addresses, according to reporting by Genfinity and TRM Labs.
The total loss figure varies by source. TRM Labs pegged the figure at $116 million as of its August analysis. TechCrunch reported $130 million. CP24, citing Canadian law enforcement sources, referenced $140 million. The discrepancy reflects timing differences and varying BTC price assumptions across reporting windows.
TRM Labs identified at least 15 distinct threat actors involved across the four waves, with transaction construction differing meaningfully between groups. The firm characterized later participants as "likely opportunistic copycats" who independently exploited the same vulnerability once the attack vector became apparent from on-chain observation of Wave 1.
Fund laundering has been limited. TRM traced one deposit of 64.9 BTC into the Wasabi CoinJoin mixer and 200 ETH routed through Tornado Cash as of August 4. The majority of stolen funds remained in attacker-controlled addresses with no layering or mixing activity. This pattern — large balances sitting idle — is consistent with either operational caution or attacker inexperience.
Coinkite CEO Rodolfo Novak stated the company suspects AI-assisted computation may have accelerated the brute-forcing process, though no evidence has been published to substantiate this claim. The 40-bit entropy window is brute-forceable with conventional hardware.
The exploit's second-order effects exceeded the direct losses by orders of magnitude. Glassnode data shows long-term holder (LTH) supply falling from approximately 15 million BTC to 14.7 million BTC in the week following disclosure — a 210,000 BTC decline worth roughly $13.4 billion at prevailing prices.
Glassnode characterized the movement as migration rather than liquidation: "The data indicates holders are migrating their coins to new wallets rather than sending to exchanges." This interpretation is supported by the absence of a corresponding spike in exchange inflow metrics.
The timing is atypical. Historical LTH supply declines have correlated with market peaks and profit-taking. This event occurred with Bitcoin trading near $64,000, approximately 50% below its October 2025 record high. The security-driven nature of the migration distinguishes it from standard distribution behavior.
For Coldcard's installed base, the implication is stark: anyone who generated a seed on affected firmware must treat that seed as compromised regardless of whether their funds have been stolen. Coinkite's advisory instructs users to generate a new seed on updated or unaffected hardware and migrate all funds.
The Coldcard incident has produced a measurable shift in capital flows that maps onto the long-standing custody debate.
Spot Bitcoin ETFs recorded $620 million in daily inflows during the period following disclosure, according to data cited by CryptoBriefing. The ARK 21Shares Bitcoin ETF accounted for a substantial portion of the flow. Bloomberg senior ETF analyst Eric Balchunas noted the correlation but cautioned that "there is no evidence establishing that Coldcard users directly caused the ETF inflows."
Balchunas argued that spot Bitcoin ETFs "remove seed-management risk entirely for investors who only want price exposure," and that institutional custodians' role in ETF infrastructure — once seen as a liability by self-custody advocates — "may all of a sudden seem like a feature."
Binance co-founder Changpeng Zhao stated that "storing crypto on centralized exchanges may now be statistically safer than self-custody," citing aggregate data showing cumulative losses from self-custody incidents exceeding those from exchange hacks.
TRM Labs offered a more measured assessment: the incident "has further confirmed that self-custody only relocates risks and does not remove them."
The economic framing matters. Self-custody eliminates counterparty risk (exchange insolvency, regulatory seizure) but introduces operational risk (key management, firmware integrity, physical security). The Coldcard exploit demonstrates that operational risk in self-custody extends beyond user error to supply-chain defects embedded at the manufacturer level — a risk category that individual users have no practical means of auditing.
Ledger published a detailed technical post confirming its devices are unaffected, citing use of a True Random Number Generator (TRNG) embedded in its Secure Element chip that produces 256 bits of entropy per seed. Trezor issued similar assurances.
Both Trezor and Foundation Devices warned users about a surge in phishing attempts exploiting the Coldcard incident. Scammers are pushing malicious firmware downloads and recovery-phrase harvesting schemes, according to reports by Decrypt and ForkLog.
The hardware wallet market — valued at approximately $720 million in 2026, according to Mordor Intelligence — is projected to reach $2.25-2.58 billion by 2031. Ledger, which has shipped over 8 million devices and claims to secure more than 20% of the world's crypto assets by value, stands to benefit from competitive repositioning. Whether the Coldcard incident permanently damages the broader hardware wallet category or concentrates market share among surviving players remains to be determined.
Coinkite halted shipments and destroyed remaining inventory manufactured with vulnerable firmware. The company shipped emergency firmware patches on July 31, one day after Wave 1, but acknowledged the patches cannot repair seeds already generated on compromised firmware.
Victims are coordinating class-action proceedings against Coinkite, according to reporting by Bitcoin.com and CoinSpectator. As of early August 2026, no formal lawsuit has been filed; the effort remains in the coordination and evidence-gathering phase.
Legal experts cited in media coverage are divided on Coinkite's liability. Some argue there is "a credible legal basis to investigate responsibility" based on product defect and negligence theories. Others note that open-source firmware, user agreements, and the decentralized nature of Bitcoin custody complicate traditional product liability frameworks.
Coinkite has suspended its standard data-deletion protocols pending potential legal proceedings, according to CryptoTimes. The company's retention of customer email addresses — unusual for a privacy-focused Bitcoin company — has drawn additional criticism.
The case could establish precedent for hardware wallet manufacturer liability, a question that has not been tested in court. The outcome will signal whether hardware wallet makers face the same product-safety obligations as manufacturers of traditional financial infrastructure equipment.
The Coldcard exploit illustrates a structural feature of self-custody economics: loss absorption is entirely borne by end users. There is no deposit insurance, no lender of last resort, and no recourse mechanism beyond civil litigation with uncertain prospects.
The $116 million in direct theft represents value permanently extracted from the Bitcoin economy. Unlike exchange hacks, where a corporate entity may absorb losses (as FTX creditors experienced through bankruptcy proceedings), hardware wallet exploits produce uninsured, distributed losses across thousands of individuals.
The 210,000 BTC migration, while not a loss event, carries real economic cost: transaction fees, time spent on key rotation, and the opportunity cost of operational disruption for affected users. For the broader self-custody ecosystem, the reputational cost functions as a tax on adoption — raising the perceived risk premium of self-custody relative to custodial alternatives.
The hardware wallet market's projected growth to $2.25 billion by 2031 implicitly prices in a level of manufacturer reliability that the Coldcard incident calls into question. The $720 million market producing a $116 million loss event in a single firmware defect suggests the industry's quality assurance infrastructure has not scaled with its economic exposure.
The Coldcard exploit is not a story about a single company's firmware error. It is a stress test of the self-custody model's implicit assumption: that hardware wallet manufacturers maintain the same quality assurance standards as the financial infrastructure they claim to replace.
A $720 million industry that produces a $116 million single-point-of-failure event has a ratio problem. The Coldcard incident exposed a five-year window during which an estimated tens of thousands of devices shipped with fundamentally compromised entropy — a defect invisible to users, undetectable by external audit, and exploitable without physical access.
The behavioral data — 210,000 BTC migrated, $620 million flowing into ETFs — suggests a portion of the market is repricing the risk of self-custody in real time. Whether this repricing proves durable or temporary will depend on whether the hardware wallet industry treats the Coldcard exploit as an isolated manufacturing defect or as evidence of systemic quality assurance gaps across the sector.
The legal proceedings against Coinkite, if they proceed, will determine whether "open-source" and "user responsibility" remain effective liability shields for hardware wallet manufacturers, or whether the industry faces the same product-safety obligations as any other manufacturer of security-critical equipment.