Coldcard Hack Exposes $70M in Bitcoin to Theft Through Guessable Seeds
The Coldcard hack has drained over $70 million in Bitcoin from more than 1,000 wallets in just 41 minutes.
The attack occurred on July 30, 2026, when an attacker exploited a firmware bug that had been present since March 2021. The bug allowed the attacker to generate candidate seeds and derive addresses without needing access to the hardware itself.
Coinkite, the Canadian firm behind Coldcard, shipped an emergency firmware update on July 31 to affected users, but updating the firmware does not change or repair existing seeds. Affected users must generate a fresh seed on fixed firmware and move their funds over.
The hack has raised concerns about the security of Bitcoin self-custody, with some analysts expecting holders to lean toward regulated custodians and spot Bitcoin ETFs.