Coldcard Bitcoin Wallet Hack Exceeds $100 Million as Fourth Wave Looms
A massive Bitcoin wallet hack has left over $100 million in losses, with suspected fourth wave of attacks potentially pushing total losses to $130 million. The breach targets a firmware flaw introduced in March 2021, which still remains active.
The exploit exploits a build error in Coinkite's firmware version 4.0.1, released around March 2021. Affected devices, primarily Coldcard Mk2 and Mk3 models, failed to use the hardware true random number generator (TRNG) correctly during seed creation, instead falling back on a weaker software-based pseudorandom number generator.
Attackers pre-computed candidate seeds, matched them to on-chain addresses holding Bitcoin, and swept single-signature wallets without ever touching a physical device. The first major sweep hit around July 30, 2026, draining over 1,000 BTC from more than 1,200 addresses in under an hour.
Ripple CTO Emeritus David Schwartz framed the hack within a broader conversation on outlier risk in crypto custody, drawing comparisons to historic TradFi failures such as MF Global in 2011. However, he noted the key difference: insurance availability does not currently extend to self-custody crypto losses.