$130 Million Coldcard Hack Exposes Vulnerability in Hardware Wallets
A firmware flaw in Coldcard hardware wallets has triggered one of the biggest Bitcoin security events of 2026, with losses now estimated at over $130 million.
The vulnerability, which dates back to March 2021, weakened the randomness of seed generation on affected devices, making wallets brute-forceable without any physical access. At least three waves of attacks have drained funds from 7,300 victim wallets, and a suspected fourth wave could push total losses even higher.
Bitcoin active addresses surged to around 980,000 per day following the exploit, according to Glassnode, which described it as 'an operational security response, not a change in market conviction.'