Close Menu
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
What's Hot

Cursor Launches Origin Code Hosting Feature for Paid Users

August 18, 2026

CATL Mandates Carbon Footprint Requirements For New Suppliers By 2027

August 18, 2026

N3XT Bank Wins Wyoming Approval for Instant Payments

August 18, 2026

CME Group Plans Compute Futures Launch For October 2026

August 18, 2026

Japan 30-Year Bond Yield Rises 4.5 Basis Points to 4.12%

August 18, 2026

Monad Foundation Completes $60M Liquidity Program for MON Investors

August 18, 2026

Fitch Affirms Intel at BBB and Raises Outlook to Stable

August 18, 2026

Binance Shared Russian Customer Data With Investigators After Exit

August 18, 2026

Neynar Begins Search for New Operators for Farcaster and Clanker

August 18, 2026

Robinhood Chain Total Value Locked Surges Past $540 Million

August 18, 2026
Facebook X (Twitter) Instagram
Daily Crypto News
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
Dashboard
Daily Crypto News
Home»Reviews»Coldcard hack losses surpass $115 million due to critical firmware flaw
Coldcard hack losses surpass $115 million due to critical firmware flaw
Confirmed losses from the Coldcard Bitcoin hack have exceeded $115 million, with totals potentially reaching $130M. The theft stems from a firmware bug in Co...
Reviews

Coldcard hack losses surpass $115 million due to critical firmware flaw

Michael FawnBy Michael FawnAugust 18, 20265 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Coldcard hack losses have officially exceeded $115 million following a critical firmware vulnerability in one of Bitcoin’s most popular hardware wallets. According to the latest figures from Galaxy Research, the ongoing theft from Coldcard devices, which began on July 30, 2026, stems from a long-dormant bug in products made by the Canadian company Coinkite.

The exploit has shaken confidence in a device long considered a bastion of secure self-custody. Galaxy’s investigation suggests total losses could ultimately climb as high as $130 million as more victims come forward and on-chain analysis continues. The firm has been in contact with over 200 victims to track the stolen funds and gather intelligence on the attackers.

How the firmware bug caused massive Coldcard hack losses

The security failure lies not in the hardware itself, but in the firmware that controls it. Coinkite confirmed that a bug introduced in its Coldcard Mk3 devices back in March 2021 is the root cause. The flaw, present in firmware versions starting from 4.0.1, created a critical failure in the wallet’s seed phrase generation process.

Under normal circumstances, the Coldcard relies on a dedicated hardware component, a true random number generator (TRNG), to create the entropy needed for a secure private key. This is a cornerstone of its security model. However, the bug caused the device to silently fall back to a weak software-based pseudorandom number generator (PRNG) instead.

This fallback rendered the seed phrases predictable and guessable for attackers with sufficient knowledge of the vulnerability. Because the failure was silent, users had no indication that their keys were being generated with a flawed, less-secure method. Coinkite stated the bug “silently went unnoticed” as “its potential impact grew with every release” of its products.

This distinction between a hardware and software flaw is critical. While the physical device remained secure, the compromised software it ran effectively negated its primary security feature. It created a situation where attackers could remotely reconstruct private keys without ever needing physical access to the wallets.

Galaxy Research tracks multiple attackers

The investigation by Galaxy Research paints a picture of a widespread, opportunistic attack rather than a single coordinated heist. Early analysis from the firm indicated that at least 15 separate attackers were independently exploiting the same vulnerability. This suggests the flaw may have been discovered and passed around in underground forums before it was publicly disclosed.

In a post on X (formerly Twitter), Galaxy Research provided updates based on its work with victims. The $115 million figure was calculated based on the price of bitcoin at the time the coins were stolen. The rising tally reflects the ongoing nature of the exploit, as attackers work through wallets that have not yet been updated or emptied.

The data also reveals interesting patterns about the stolen funds. Previous research from Galaxy found that the typical bitcoin stolen had remained untouched for an average of 3.5 years. A striking 88% of the pilfered funds were at least one year old, indicating the victims were overwhelmingly long-term holders who believed their assets were secure in deep cold storage.

This profile of the victims highlights the misplaced sense of security the bug created. These were not active traders but investors who followed the industry’s best practices for long-term holding, only to be compromised by a latent software flaw in the very device meant to protect them.

Coinkite’s response and the flight to safety

In the days following the first reported thefts on July 30, Coinkite issued urgent advisories to its users. The company urged all Coldcard owners, particularly those with Mk3 models, to immediately move their funds to a new wallet with a securely generated seed phrase. They also released updated firmware to patch the vulnerability for users setting up new devices.

The incident has triggered a notable shift in user behavior. Many cautious investors, rattled by the news, have been moving their bitcoin off their hardware wallets entirely. Some have transferred funds to competitor hardware wallet brands, while others have taken the surprising step of moving assets back onto regulated cryptocurrency exchanges, temporarily abandoning self-custody.

This reaction, though understandable, runs counter to the long-held crypto mantra of “not your keys, not your coins.” It underscores the severity of the situation. When a leading hardware wallet fails so catastrophically, it can make the custodial risk of an exchange seem, for some, like the lesser of two evils.

The long-term impact on the hardware wallet market and user trust remains to be seen.

A difficult lesson for the self-custody landscape

The Coldcard hack serves as a stark and costly reminder that no security solution is infallible. The promise of hardware wallets is the isolation of private keys from insecure, internet-connected environments like laptops and smartphones. They are designed to be a black box for signing transactions, ensuring keys never leave the device.

However, this incident proves that the integrity of the software running within that black box is just as important as the physical isolation it provides. A flaw in the firmware can be just as devastating as a virus on a PC. It shifts the trust assumption from just the hardware to the entire software supply chain and the diligence of the manufacturer’s developers.

For the broader industry, this event will likely trigger a renewed focus on firmware verification, open-source auditing, and the importance of truly random number generation. It highlights the immense responsibility placed on manufacturers of security hardware and the catastrophic consequences when that trust is broken, even unintentionally.

As the final losses are tallied, the lessons from this expensive failure will reverberate through the crypto security space for years to come.

bitcoin theft coinkite vulnerability coldcard hack losses galaxy research report hardware wallet security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

SafePal data breach exposes shipping details of 39,798 wallet buyers

August 17, 2026

UKey hardware wallet ecosystem: Core 26, Seed Ring, and the rumored Zero Ring

August 16, 2026

Gemini Credit Card Revenue Triples Amidst Surging Fraud Losses in Q2 2026

August 15, 2026

Tether secures unqualified KPMG audit for reserves, setting new industry standard

August 14, 2026

Recent Posts

  • Cursor Launches Origin Code Hosting Feature for Paid Users
  • CATL Mandates Carbon Footprint Requirements For New Suppliers By 2027
  • N3XT Bank Wins Wyoming Approval for Instant Payments
  • CME Group Plans Compute Futures Launch For October 2026
  • Japan 30-Year Bond Yield Rises 4.5 Basis Points to 4.12%
Top Posts

SafePal data breach exposes shipping details of 39,798 wallet buyers

August 17, 2026

UKey hardware wallet ecosystem: Core 26, Seed Ring, and the rumored Zero Ring

August 16, 2026

Gemini Credit Card Revenue Triples Amidst Surging Fraud Losses in Q2 2026

August 15, 2026

Stay updated with the latest crypto news, market trends, and expert insights. We provide accurate and timely information to help you make better decisions.

Facebook X (Twitter) Instagram Pinterest YouTube
Our Resources
  • About Us
  • Privacy Policy
  • Editorial Policy
  • Legal Disclaimer
  • Contact us
Categories
  • Altcoins
  • Prediction
  • Opinion
  • Guides
  • Reviews
  • Bitcoin
  • Ethereum
Recent Posts
  • Cursor Launches Origin Code Hosting Feature for Paid Users
  • CATL Mandates Carbon Footprint Requirements For New Suppliers By 2027
  • N3XT Bank Wins Wyoming Approval for Instant Payments
  • CME Group Plans Compute Futures Launch For October 2026
© 2026 Daily Crypto News

Type above and press Enter to search. Press Esc to cancel.