A firmware bug in Coldcard hardware wallets made it possible to reproduce wallet seeds from a narrow, guessable set of device and timing states, allowing attackers to steal funds without phishing, malware, or physical device access. Galaxy Research estimates the theft may have reached roughly 2,055 BTC, around $130 million and counting.
The Vulnerability
A build error in Coldcard firmware versions 4.0.1 through 4.1.9 swapped genuine hardware randomness for a predictable software substitute. The firmware failed to properly seed the random number generator during wallet creation, shrinking the odds of guessing a wallet's seed from effectively impossible to computationally feasible.
Block's Engineering team, which investigated the incident after user reports, identified the pattern: "A build error swapped genuine hardware randomness for a predictable software substitute, shrinking the odds of guessing a wallet's seed from cosmic to countable."
Attackers did not need to interact with victims. They ran the numbers on their own machines, derived candidate addresses based on the reduced entropy space, and matched them against the public blockchain. When a match hit, the private key followed immediately.
Discovery and Response
Coldcard owners noticed the theft first—the way victims usually do: funds gone with no transaction they remembered signing. On July 30, 2026, between 01:10:20 and 01:51:26 UTC, 1,196 addresses were drained for 1,082.65 BTC across blocks 960,183 through 960,191.
Block's Engineering team started investigating the same day, working from user reports rather than an automated scanner. Galaxy Research used that footprint to map the flow the following day, tracing 1,082.65 BTC (roughly $70 million at the time) from the addresses it flagged.
Coinkite, Coldcard's manufacturer, issued a preliminary advisory the same day, warning Mk3 owners whose seeds had been generated on firmware 4.0.1 through 4.1.9. NVK, Coinkite's CEO, posted a public apology the next morning, taking responsibility for the firmware failure and urging affected users to move funds to newly generated seeds.
A firmware update alone would not fix the problem. Coinkite later clarified that seeds generated before the patch needed to be replaced outright, not simply updated.
Escalating Losses
The loss estimates grew rapidly as investigators identified more affected wallets. By August 3rd, Galaxy Research said losses had exceeded $100 million. The firm's high-confidence tally was 1,596 BTC stolen from roughly 7,300 addresses across three confirmed waves and 14 smaller incidents.
Galaxy identified a potential fourth wave but excluded it from the high-confidence tally due to insufficient victim confirmation. Including that unconfirmed activity would have pushed the total higher still.
The attacker count remained uncertain, but TRM Labs reported at least 15 distinct attackers. Most of the stolen funds remained untouched as of early August, suggesting the attackers were waiting for the investigation to lose momentum before moving the Bitcoin.
Self-Custody Implications
The Coldcard incident undermines a fundamental premise of hardware wallet security: that offline signing inherently protects private keys. When the seed generation process itself is compromised, offline devices become vulnerabilities rather than safeguards.
Victims of the Coldcard bug did everything self-custody preaches: they used hardware wallets, kept devices offline, and avoided exposing private keys to network-connected systems. Yet they lost funds anyway because the seed was never truly random to begin with.
The incident raises questions about hardware wallet manufacturing processes and testing. A build error that replaces hardware randomness with predictable software entropy should have been caught during quality assurance or independent security reviews.
Recommendations for Coldcard Users
Coinkite's guidance for affected users is clear: any seed generated on firmware 4.0.1 through 4.1.9 must be considered compromised. Users should:
- Generate a new seed on firmware 4.2.0 or later
- Move all funds from addresses derived from the old seed
- Verify the new seed was created on patched firmware before trusting it
Users who are unsure which firmware version generated their seed should assume the worst and migrate funds as a precaution.
Broader Security Lessons
The Coldcard vulnerability illustrates that self-custody is only as secure as the entropy source backing the seed. Hardware wallets are not immune to software bugs, and manufacturing errors can compromise the foundational randomness that seed phrases rely on.
For the industry, the incident underscores the importance of independent entropy verification and transparency about seed generation processes. Users should be able to verify that their hardware wallet used genuine hardware randomness during seed creation, not trust blindly in the device's claims.
The $130 million and counting loss represents one of the largest hardware wallet exploits in crypto history—and one of the few that required no victim interaction whatsoever.