In late July 2026, one of the most respected Bitcoin-only hardware wallets suffered a major security failure. Coinkite's Coldcard devices, long praised for air-gapped security and strong self-custody practices, became the target of a large-scale theft that has so far drained an estimated $116 million to $130 million in Bitcoin.
This was not a phishing attack, a physical theft, or a user mistake. It was a firmware flaw from 2021 that weakened the randomness used to generate seed phrases, making private keys brute-forceable.
What Happened
Starting around July 30, 2026, attackers began sweeping funds from thousands of Coldcard-generated wallets. The first major wave moved roughly 594 BTC (about $38 million at the time) from around 500 addresses in under 30 minutes. Additional waves followed over the next several days.
By early August, security firms including Galaxy Research and TRM Labs estimated total losses between 1,800 and 2,000 BTC, valued at approximately $116 million to $130 million across more than 5,000 addresses. Multiple independent actors appear to have exploited the same vulnerability.
Victims included careful long-term holders who kept devices offline, stored seeds in steel, and never connected the wallet to the internet. Many reported doing "everything right" and still losing funds.
The Technical Flaw
The root cause traces back to Coldcard firmware version 4.0.0 / 4.0.1 released in March 2021.
Due to a build configuration error, some devices fell back to a weak software-based random number generator instead of the hardware entropy source when creating seed phrases. This reduced effective key strength from the expected 128 bits of entropy down to as low as ~40 bits on affected devices (higher but still insufficient on others).
At 40 bits, modern computing power makes brute-forcing feasible. Attackers did not need physical access to the device or the seed phrase. They could regenerate the private keys offline and drain the associated addresses.
Important notes from Coinkite and researchers
—Seeds generated on vulnerable firmware remain at risk even after updating the device.
—Updating firmware only protects newly generated seeds.
—Affected users must generate entirely new wallets and move funds.
Company Response and Ongoing Fallout
Coinkite publicly acknowledged the issue, released patched firmware, and urged users who generated seeds on affected versions to migrate funds immediately using updated best practices.
Other hardware wallet makers (including Trezor and Foundation) reported a sharp rise in phishing attempts that referenced the Coldcard incident, with scammers impersonating support or "security audits."
The event has reignited debate about the practical risks of self-custody, even among experienced Bitcoiners, and highlighted how a single long-standing firmware mistake can undermine years of careful operational security.
Key Lessons
—Hardware is only as strong as its firmware and entropy source. Air-gapping does not protect against a flaw that weakens seed generation itself.
—Firmware age matters. A bug introduced in 2021 remained exploitable for five years.
—Migration is the only real fix for weak seeds. Patching the device is not enough if the original seed is compromised.
—Phishing risk spikes after major incidents. Always verify communications and never enter seed phrases on websites or apps.
—Diversification and verification remain essential. Even highly regarded devices can fail. Regular security reviews, multi-sig where appropriate, and testing recovery processes reduce single points of failure.
Final Thoughts
The Coldcard incident is a reminder that no tool is perfect. Self-custody remains powerful, but it requires ongoing vigilance, including awareness of firmware history, entropy quality, and the need to migrate when vulnerabilities are disclosed.
If you hold significant value on any hardware wallet (Coldcard or otherwise), review the manufacturer's latest advisories, confirm your seed generation process, and consider whether your current setup still meets your risk tolerance.
Stay safe, verify everything, and never share your seed phrase.


