Coldcard Firmware Flaw Drains $88.6 Million in Bitcoin Across Multiple Waves

7 min read
4 views
Aug 2, 2026

A shocking vulnerability in popular Coldcard hardware wallets has resulted in over $88 million drained in Bitcoin. Three waves of attacks hit thousands of addresses — here's what we know so far and why it should concern every self-custody user.

Financial market analysis from 02/08/2026. Market conditions may have changed since publication.

Imagine waking up to find that years of carefully secured Bitcoin have vanished overnight. For hundreds of Coldcard users, this nightmare became reality recently as losses climbed to a staggering $88.6 million. What started as a concerning report quickly escalated into one of the more significant self-custody incidents in recent memory.

I’ve followed crypto security stories for years, and this one hits different. Hardware wallets are supposed to be the gold standard for keeping your keys safe. When even those fail due to a subtle firmware issue, it forces everyone in the space to pause and rethink their assumptions about safety.

The Growing Scale of the Coldcard Incident

Recent analysis pushed the total Bitcoin drained from addresses tied to this vulnerability up to roughly 1,367 BTC. At current prices, that’s approximately $88.6 million. The figures come from detailed on-chain tracking that revealed not one, but three distinct waves of activity targeting affected seeds.

This isn’t just a single opportunistic sweep. Researchers identified thousands of addresses involved across multiple days. The pattern suggests sophisticated operators who understood exactly how to exploit the weakness once it became apparent.

What makes this particularly troubling is that Coldcard has long enjoyed a reputation for being one of the more paranoid and security-focused hardware options available. Users who chose it often did so precisely because they wanted maximum control and minimal trust in third parties.

Breaking Down the Three Attack Waves

The first wave hit hard and fast on July 30. In just 41 minutes, attackers drained 1,082.65 BTC from 1,196 addresses. The transactions shared distinctive features — specific fee rates and no change outputs — that made them stand out to analysts monitoring the blockchain.

This initial surge happened roughly 30 hours before any public warning went out. By the time many users heard about potential issues, significant damage had already occurred. The speed was breathtaking and highlighted how quickly funds can move once a vulnerability is actively exploited.

The transactions appeared coordinated and highly efficient, suggesting the attackers had prepared their approach in advance.

A second wave followed on July 31, pulling another 76 BTC from over 1,400 additional addresses. Then came the third wave with 207 BTC taken from nearly 1,900 more addresses. Together these events paint a picture of persistent, methodical exploitation rather than a one-off incident.

Interestingly, the third wave showed different characteristics. Instead of consolidated collector addresses, funds moved to separate destinations. This variation might indicate either evolving tactics or potentially different actors, though proving that definitively on-chain remains challenging.

Understanding the Root Cause: A Firmware Integration Error

At its core, the problem stemmed from issues in how the device handled random number generation during seed creation. A series of integration problems meant the hardware random number generator didn’t contribute properly in certain firmware versions. Instead, a software fallback kicked in that proved far more predictable than intended.

This bug affected seeds generated on specific firmware releases spanning several years. Mk2 and Mk3 devices with firmware between 4.0.1 and 4.1.9 were particularly exposed. Later models had some mitigations but still fell short of full entropy targets in certain scenarios.

Think about that for a moment. People who bought these devices to protect their wealth against sophisticated threats ended up with seeds that had significantly reduced security — sometimes as low as 40 bits of effective entropy for earlier versions. That’s a far cry from the 128+ bits users expected.

Why This Vulnerability Was So Dangerous

Bitcoin’s strength lies in its private keys. If someone can guess or brute-force those keys, your funds are gone with no recourse. Most hardware wallet compromises happen through user error — phishing, malware on connected computers, or poor seed backup practices. This case was different because the weakness originated in the device itself during setup.

Users who followed best practices — buying directly from the manufacturer, verifying firmware, and generating seeds offline — still found themselves at risk through no fault of their own. That’s a bitter pill for the self-custody community that prides itself on personal responsibility.

  • Reduced entropy made seeds vulnerable to practical attacks
  • Attacks could be executed without physical access to devices
  • Multiple waves showed sustained exploitation over days
  • On-chain patterns allowed researchers to estimate total impact

The manufacturer has taken responsibility and released fixes, but existing seeds can’t be patched. Users must create entirely new seeds and migrate funds carefully. This process itself carries risks if not done thoughtfully.

The Human Side of Hardware Wallet Disasters

Beyond the dollar figures, there are real people behind these addresses. Some likely represented life savings, retirement funds, or inheritances. Others might have been smaller stacks that still carried enormous emotional weight. Watching funds drain with no ability to stop it must have been devastating.

In my experience covering these stories, the psychological impact often lingers long after any financial recovery. Trust in the ecosystem takes a hit. Even those not directly affected start questioning their own setups and wondering what hidden vulnerabilities might exist in other popular tools.

This incident serves as a reminder that no solution is perfect. The pursuit of better security is ongoing, and we all need to stay vigilant even when using respected brands.

Technical Details That Matter

For those interested in the deeper mechanics, the issue involved MicroPython components and how entropy sources were combined. A code change years ago introduced the problematic fallback behavior. Independent researchers confirmed the weakness and noted active exploitation in the wild.

Estimates suggest the vulnerable seeds had search spaces that sophisticated attackers could feasibly target given enough resources and motivation. Later device versions incorporated additional entropy from secure elements, but even those didn’t reach ideal levels before fixes were deployed.

Seeds created with dice rolls or other strong manual methods may offer better protection, but caution is still advised.

The company recommends dice-based generation as a potential mitigation for those who haven’t migrated yet, combined with strong passphrases. However, the safest path remains creating fresh seeds on fixed firmware and carefully transferring assets.

Broader Implications for Self-Custody

This event raises important questions about the hardware wallet market. How many users verify firmware signatures religiously? How often do people audit the supply chain for their devices? Are we over-relying on brand reputation rather than verifiable security properties?

I’ve always believed self-custody represents true ownership in Bitcoin, but incidents like this show it’s not as simple as “not your keys, not your coins.” The keys need to be generated and stored under conditions we can actually verify and trust.

Perhaps this will accelerate development of new verification tools, better open-source auditing, or even multi-vendor approaches where users combine elements from different manufacturers to reduce single points of failure.

What Should Affected Users Do Now?

If you own a Coldcard and generated seeds on affected firmware, the priority is migration. Install the latest fixed firmware, create a new seed, verify everything thoroughly, and move funds in stages with test transactions first. Keep your old backup until the process completes successfully.

  1. Update to the latest secure firmware version immediately
  2. Generate a completely new seed phrase on the fixed device
  3. Verify the backup by checking addresses match
  4. Send a small test amount before moving larger balances
  5. Consider using dice rolls for additional entropy if preferred

Even if you weren’t affected directly, this is an excellent time to review your overall security posture. Are you using outdated firmware elsewhere? Do you have proper backups? Have you tested recovery procedures recently?

Lessons for the Entire Crypto Community

Security isn’t a set-it-and-forget-it proposition. Even well-respected projects can harbor subtle bugs that persist for years before discovery. The transparency shown by the manufacturer in acknowledging the issue and providing fixes deserves credit, but the real test will be how the broader ecosystem responds with improved practices.

We’ve seen similar issues in other areas of crypto before — smart contract bugs, exchange hacks, bridge exploits. Each teaches us something new about where assumptions break down. In this case, the assumption that hardware entropy sources would always behave as documented proved costly for some.

Moving forward, greater emphasis on reproducible builds, independent security audits, and perhaps formal verification methods could help reduce similar surprises. Users should demand more transparency and perhaps participate more actively in testing and review processes when possible.

The Role of On-Chain Analysis in Understanding Attacks

One positive aspect of this story is how effectively researchers used blockchain data to track and quantify the losses. Distinct transaction patterns — fee rates, output types, timing — allowed clustering of related activity even without knowing the exact attacker identities.

This kind of analysis helps the community understand the scope of problems quickly. It also demonstrates that while Bitcoin offers pseudonymity, large scale movements can still be observed and studied. The public nature of the ledger cuts both ways.

Future incidents will likely see even faster response times as monitoring tools improve. That’s a net benefit for security overall, even if it feels invasive to some.

Looking Ahead: Rebuilding Confidence

The crypto space has weathered numerous setbacks and emerged stronger each time. This incident, while painful for those impacted, provides valuable data points for improving hardware wallet design and user education.

Manufacturers will likely implement more rigorous testing for entropy generation. Users might become more diligent about firmware versions and migration procedures. The conversation around seed generation best practices has already been elevated.

Perhaps most importantly, it reminds us why Bitcoin’s decentralized nature matters. No single company or device controls the network. While individual users can suffer losses, the protocol itself continues functioning exactly as designed.


As someone who believes deeply in the importance of self-custody, I hope this event ultimately leads to better tools and practices rather than driving people back toward centralized solutions. The path to secure Bitcoin ownership isn’t always smooth, but the destination remains worth pursuing.

Stay safe out there. Verify your setups, keep learning, and never stop questioning whether your security measures are as robust as you think they are. The Bitcoin ecosystem needs vigilant participants now more than ever.

This situation continues developing as more analysis emerges and users complete their migrations. The final loss numbers may shift slightly, but the core lessons about careful device management and ongoing vigilance will likely endure long after the dust settles.

The digital currency is being built to eventually perform all the functions that gold does—but better.
— Michael Saylor
Author

Steven Soarez passionately shares his financial expertise to help everyone better understand and master investing. Contact us for collaboration opportunities or sponsored article inquiries.

Related Articles

?>