Coldcard hack losses have officially exceeded $115 million following a critical firmware vulnerability in one of Bitcoin’s most popular hardware wallets. According to the latest figures from Galaxy Research, the ongoing theft from Coldcard devices, which began on July 30, 2026, stems from a long-dormant bug in products made by the Canadian company Coinkite.
The exploit has shaken confidence in a device long considered a bastion of secure self-custody. Galaxy’s investigation suggests total losses could ultimately climb as high as $130 million as more victims come forward and on-chain analysis continues. The firm has been in contact with over 200 victims to track the stolen funds and gather intelligence on the attackers.
How the firmware bug caused massive Coldcard hack losses
The security failure lies not in the hardware itself, but in the firmware that controls it. Coinkite confirmed that a bug introduced in its Coldcard Mk3 devices back in March 2021 is the root cause. The flaw, present in firmware versions starting from 4.0.1, created a critical failure in the wallet’s seed phrase generation process.
Under normal circumstances, the Coldcard relies on a dedicated hardware component, a true random number generator (TRNG), to create the entropy needed for a secure private key. This is a cornerstone of its security model. However, the bug caused the device to silently fall back to a weak software-based pseudorandom number generator (PRNG) instead.
This fallback rendered the seed phrases predictable and guessable for attackers with sufficient knowledge of the vulnerability. Because the failure was silent, users had no indication that their keys were being generated with a flawed, less-secure method. Coinkite stated the bug “silently went unnoticed” as “its potential impact grew with every release” of its products.
This distinction between a hardware and software flaw is critical. While the physical device remained secure, the compromised software it ran effectively negated its primary security feature. It created a situation where attackers could remotely reconstruct private keys without ever needing physical access to the wallets.
Galaxy Research tracks multiple attackers
The investigation by Galaxy Research paints a picture of a widespread, opportunistic attack rather than a single coordinated heist. Early analysis from the firm indicated that at least 15 separate attackers were independently exploiting the same vulnerability. This suggests the flaw may have been discovered and passed around in underground forums before it was publicly disclosed.
In a post on X (formerly Twitter), Galaxy Research provided updates based on its work with victims. The $115 million figure was calculated based on the price of bitcoin at the time the coins were stolen. The rising tally reflects the ongoing nature of the exploit, as attackers work through wallets that have not yet been updated or emptied.
The data also reveals interesting patterns about the stolen funds. Previous research from Galaxy found that the typical bitcoin stolen had remained untouched for an average of 3.5 years. A striking 88% of the pilfered funds were at least one year old, indicating the victims were overwhelmingly long-term holders who believed their assets were secure in deep cold storage.
This profile of the victims highlights the misplaced sense of security the bug created. These were not active traders but investors who followed the industry’s best practices for long-term holding, only to be compromised by a latent software flaw in the very device meant to protect them.
Coinkite’s response and the flight to safety
In the days following the first reported thefts on July 30, Coinkite issued urgent advisories to its users. The company urged all Coldcard owners, particularly those with Mk3 models, to immediately move their funds to a new wallet with a securely generated seed phrase. They also released updated firmware to patch the vulnerability for users setting up new devices.
The incident has triggered a notable shift in user behavior. Many cautious investors, rattled by the news, have been moving their bitcoin off their hardware wallets entirely. Some have transferred funds to competitor hardware wallet brands, while others have taken the surprising step of moving assets back onto regulated cryptocurrency exchanges, temporarily abandoning self-custody.
This reaction, though understandable, runs counter to the long-held crypto mantra of “not your keys, not your coins.” It underscores the severity of the situation. When a leading hardware wallet fails so catastrophically, it can make the custodial risk of an exchange seem, for some, like the lesser of two evils.
The long-term impact on the hardware wallet market and user trust remains to be seen.
A difficult lesson for the self-custody landscape
The Coldcard hack serves as a stark and costly reminder that no security solution is infallible. The promise of hardware wallets is the isolation of private keys from insecure, internet-connected environments like laptops and smartphones. They are designed to be a black box for signing transactions, ensuring keys never leave the device.
However, this incident proves that the integrity of the software running within that black box is just as important as the physical isolation it provides. A flaw in the firmware can be just as devastating as a virus on a PC. It shifts the trust assumption from just the hardware to the entire software supply chain and the diligence of the manufacturer’s developers.
For the broader industry, this event will likely trigger a renewed focus on firmware verification, open-source auditing, and the importance of truly random number generation. It highlights the immense responsibility placed on manufacturers of security hardware and the catastrophic consequences when that trust is broken, even unintentionally.
As the final losses are tallied, the lessons from this expensive failure will reverberate through the crypto security space for years to come.
