The Coldcard Bitcoin Thief drained over $70 million in Bitcoin by exploiting a long-standing firmware flaw in hardware wallets.
The incident, unfolding across Thursday, July 30, and Friday, July 31, 2026, has prompted urgent warnings from Coinkite, the maker of Coldcard devices, and ignited a broader discussion on hardware wallet security.
Attacker’s Sophisticated Methodology in Coldcard Bitcoin Theft
Engineer Clay Garrett of payments company Block revealed on X that investigators identified an unusual pattern in the illicit Bitcoin movements. This led to a confirmed hypothesis: the attacker operated a paid account with a well-known blockchain services provider, using it to query source addresses and facilitate the rapid sweeping of funds.
The alleged involvement of a top blockchain services provider marks a significant escalation in the tactics employed by cryptocurrency thieves. Clay Garrett, whose team at Block investigated the exploit, detailed how blockchain movements aligned with the attacker’s suspected workflow, suggesting meticulous preparation.
Garrett confirmed that internal logs from the unnamed provider matched the timing and order of the attacker’s requests. While Block explicitly stated there was no evidence the blockchain services provider knowingly aided the theft, the revelation underscores the dual-use nature of such tools, which can serve both legitimate analysis and illicit activities.
Authorities have since been notified of the findings. This advanced operational security, coupled with the systematic targeting of higher-value wallets—including one holding approximately $1.8 million—points to an attacker who possessed extensive resources and a deep understanding of blockchain forensics.
The swift execution, with hundreds of wallets drained in minutes, further implies a highly automated and pre-computed process. Researchers at Galaxy Digital also noted an unusual pattern in the coin movements, reinforcing the view that a single attacker was responsible for the coordinated drain.
Critical Firmware Flaw Enabled Massive Bitcoin Drain
The vulnerability at the heart of this extensive Coldcard Bitcoin theft stems from a firmware bug first introduced in March 2021. Coinkite traced the issue to firmware version 4.0.1 for its Coldcard Mk3 devices, which inadvertently deactivated the hardware true random number generator during seed generation.
Instead, the devices defaulted to a weaker software Pseudorandom Number Generator (PRNG). This critical oversight dramatically reduced the cryptographic strength of newly generated seeds, making them susceptible to brute-force attacks.
For affected Coldcard Mk3 devices, seeds generated after the faulty update had only about 40 bits of effective entropy, a far cry from the intended 128 bits. While later models like the Mk4, Mk5, and Q incorporated additional entropy, their effective seed strength remained compromised at approximately 72 bits—still significantly below secure levels.
Coinkite later conceded that all its models were vulnerable if seeds were generated using specific firmware releases before recent patches. This vulnerability particularly impacted single-signature wallets created without additional security measures like dice rolls or strong BIP-39 passphrases, as their private keys became predictable enough for attackers to reconstruct.
Scale of the Bitcoin Losses and Attack Timeline
The scale of the Coldcard Bitcoin theft grew rapidly once the vulnerability was actively exploited. Initial reports on Thursday, July 30, confirmed that over $35 million in Bitcoin had been drained from affected wallets.
Further investigations and subsequent thefts on Friday, July 31, pushed the total figure significantly higher. Analytics firm Onchain Lens reported that 594.48 Bitcoin, then valued at about $38.3 million, was stolen within a narrow 25-minute window between 01:31 and 01:56 UTC alone, affecting approximately 500 wallets.
Chainalysis, another blockchain analytics firm, identified 1,196 affected Unspent Transaction Outputs (UTXOs) linked to the vulnerability, totaling more than $38 million. This included the targeted draining of a single wallet holding roughly $1.8 million, highlighting the attacker’s prioritization of high-value targets.
By the end of Friday, reports indicated that the total stolen amount exceeded $70 million. Data compiled by Galaxy Digital and Block suggests that a combined 1,082.65 Bitcoins have disappeared from user wallets, with Galaxy Research estimating the total value of affected addresses at approximately $70.2 million.
Urgent Recommendations and Future of Hardware Wallet Security
In response to the widespread Coldcard Bitcoin theft, Coinkite has issued critical advice to its users. The company strongly recommends that all affected users immediately generate a brand new seed on updated hardware and transfer their funds without delay.
Crucially, simply updating the firmware on an existing vulnerable device will not resolve the issue, as the weak seed already present on the hardware remains compromised. This means any funds associated with that weak seed are perpetually at risk.
Users who previously exported a seed generated on a vulnerable Coldcard device to another wallet or system also remain exposed. Their funds are vulnerable because the fundamental cryptographic weakness of the original seed persists, regardless of where it is now stored or used.
Security experts have reiterated long-standing recommendations for safeguarding substantial Bitcoin holdings: adopting multisignature setups. This approach involves requiring multiple independent devices, ideally from different manufacturers, to authorize transactions, thereby significantly increasing resilience against single points of failure like the Coldcard firmware bug.
The incident serves as a stark reminder that even trusted hardware can harbor subtle, complex flaws with devastating consequences, emphasizing the continuous need for rigorous security practices and diversification.
Preventing Future Exploits and Lessons Learned
The Coldcard incident underscores the vital importance of true randomness in cryptographic seed generation. The unexpected fallback to a weaker PRNG demonstrates how a seemingly minor software bug can compromise the foundational security of a hardware wallet, even for devices designed with strong security principles.
This event echoes past exploits, such as the “Ill Bloom” attack, which also capitalized on cryptographic weaknesses. It highlights a critical lesson for both manufacturers and users: the integrity of random number generation is paramount. Hardware wallet providers must implement multiple layers of validation and independent audits to prevent such systemic failures from recurring.
For the broader Bitcoin community, the Coldcard Bitcoin theft reinforces the maxim of “not your keys, not your coins,” while also adding a crucial nuance: “securely generated keys.” Users are now keenly aware that the mere possession of private keys isn’t enough; their initial generation process must be unimpeachable.
The attacker’s patient strategy of sitting on knowledge of this flaw for years, targeting dormant accounts, illustrates the persistent threat landscape. This emphasizes the need for continuous vigilance, regular security reviews, and proactive measures, not just reactive responses, in the pursuit of robust Bitcoin security.
