Coldcard Hack Exposes Vulnerability in Hardware Wallets
A firmware vulnerability in Coldcard hardware wallets has led to significant losses for thousands of users. The bug, which was introduced in version 4.0.1 of the device's firmware on March 17, 2021, allowed attackers to drain approximately 1,596 to 1,719 BTC from affected addresses, with estimated losses between $100M and $111M.
Alex Thorn, from Galaxy Digital’s on-chain analysis team, confirmed the findings through on-chain forensics. The vulnerability was caused by a flaw in the device's random number generator, which generated wallet seeds with far lower entropy than expected. Some affected seeds carried as little as roughly 40 bits of entropy.
The attackers used open-source brute-force tools to reconstruct affected seeds and drain the wallets they controlled. Coinkite disclosed the vulnerability on July 30, 2026, but patching a device does not recover lost funds, and it does not fix seeds already generated on vulnerable firmware. Affected users must generate entirely new seeds on updated firmware and transfer all funds to new addresses.
Galaxy's analysis identified at least 15 distinct attackers operating across at least three confirmed theft waves, targeting roughly 7,300 addresses in total. As of August 7, confirmed stolen Bitcoin had risen to 1,719 BTC, with some reports placing potential total losses above $130M when additional suspected activity is included.