Close Menu
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
What's Hot

MoneyGram Launches First Stablecoin-Backed Visa Card in Colombia

September 10, 2026

BTCC Exchange Launches TOKEN2049 Trading Competition with $1M Prize Pool

September 10, 2026

Nasdaq, Boerse Stuttgart Ask EU to Adjust Tokenization Trial Cap

September 10, 2026

Zuckerberg: AI Boom Exists, But Not Necessarily a Bubble

September 10, 2026

Researchers Cut Bitcoin, Ethereum Quantum Attack Estimate by 50%

September 10, 2026

Nasdaq Ventures Invests $100M in Kraken Parent Payward

September 10, 2026

Liquid Network Resumes Blocks After 4,000 BTC Exploit

September 10, 2026

US Crackdown on $24B Crypto Black Market Disrupts Launderers

September 10, 2026

Coinbase CEO Predicts Bitcoin to Reach $400,000 by 2030

September 10, 2026

Tokenized Deposits Move Into Japan as Citi Plans 24/7 Corporate Remittances

September 10, 2026
Facebook X (Twitter) Instagram
Daily Crypto News
  • Markets
    • Spot Market
      • Market Overview
      • Top Gainers / Losers
      • Market Cap Charts
      • Reviews
    • Futures Market
      • Market Overview
      • Funding Rate
      • Liquidations
      • Long Short/Ratio
  • Metrics
    • Dashboard
    • Whale tracker
    • Market Heatmap
    • Funding Rates
  • News
    • Bitcoin
    • Ethereum
    • Altcoins
  • Prediction
  • Opinion
  • Calendar
  • Live Feed
Dashboard
Daily Crypto News
Home»Reviews»Coldcard hack losses surpass $115 million due to critical firmware flaw
Coldcard hack losses surpass $115 million due to critical firmware flaw
Confirmed losses from the Coldcard Bitcoin hack have exceeded $115 million, with totals potentially reaching $130M. The theft stems from a firmware bug in Co...
Reviews

Coldcard hack losses surpass $115 million due to critical firmware flaw

Michael FawnBy Michael FawnAugust 18, 20265 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

Coldcard hack losses have officially exceeded $115 million following a critical firmware vulnerability in one of Bitcoin’s most popular hardware wallets. According to the latest figures from Galaxy Research, the ongoing theft from Coldcard devices, which began on July 30, 2026, stems from a long-dormant bug in products made by the Canadian company Coinkite.

The exploit has shaken confidence in a device long considered a bastion of secure self-custody. Galaxy’s investigation suggests total losses could ultimately climb as high as $130 million as more victims come forward and on-chain analysis continues. The firm has been in contact with over 200 victims to track the stolen funds and gather intelligence on the attackers.

How the firmware bug caused massive Coldcard hack losses

The security failure lies not in the hardware itself, but in the firmware that controls it. Coinkite confirmed that a bug introduced in its Coldcard Mk3 devices back in March 2021 is the root cause. The flaw, present in firmware versions starting from 4.0.1, created a critical failure in the wallet’s seed phrase generation process.

Under normal circumstances, the Coldcard relies on a dedicated hardware component, a true random number generator (TRNG), to create the entropy needed for a secure private key. This is a cornerstone of its security model. However, the bug caused the device to silently fall back to a weak software-based pseudorandom number generator (PRNG) instead.

This fallback rendered the seed phrases predictable and guessable for attackers with sufficient knowledge of the vulnerability. Because the failure was silent, users had no indication that their keys were being generated with a flawed, less-secure method. Coinkite stated the bug “silently went unnoticed” as “its potential impact grew with every release” of its products.

This distinction between a hardware and software flaw is critical. While the physical device remained secure, the compromised software it ran effectively negated its primary security feature. It created a situation where attackers could remotely reconstruct private keys without ever needing physical access to the wallets.

Galaxy Research tracks multiple attackers

The investigation by Galaxy Research paints a picture of a widespread, opportunistic attack rather than a single coordinated heist. Early analysis from the firm indicated that at least 15 separate attackers were independently exploiting the same vulnerability. This suggests the flaw may have been discovered and passed around in underground forums before it was publicly disclosed.

In a post on X (formerly Twitter), Galaxy Research provided updates based on its work with victims. The $115 million figure was calculated based on the price of bitcoin at the time the coins were stolen. The rising tally reflects the ongoing nature of the exploit, as attackers work through wallets that have not yet been updated or emptied.

The data also reveals interesting patterns about the stolen funds. Previous research from Galaxy found that the typical bitcoin stolen had remained untouched for an average of 3.5 years. A striking 88% of the pilfered funds were at least one year old, indicating the victims were overwhelmingly long-term holders who believed their assets were secure in deep cold storage.

This profile of the victims highlights the misplaced sense of security the bug created. These were not active traders but investors who followed the industry’s best practices for long-term holding, only to be compromised by a latent software flaw in the very device meant to protect them.

Coinkite’s response and the flight to safety

In the days following the first reported thefts on July 30, Coinkite issued urgent advisories to its users. The company urged all Coldcard owners, particularly those with Mk3 models, to immediately move their funds to a new wallet with a securely generated seed phrase. They also released updated firmware to patch the vulnerability for users setting up new devices.

The incident has triggered a notable shift in user behavior. Many cautious investors, rattled by the news, have been moving their bitcoin off their hardware wallets entirely. Some have transferred funds to competitor hardware wallet brands, while others have taken the surprising step of moving assets back onto regulated cryptocurrency exchanges, temporarily abandoning self-custody.

This reaction, though understandable, runs counter to the long-held crypto mantra of “not your keys, not your coins.” It underscores the severity of the situation. When a leading hardware wallet fails so catastrophically, it can make the custodial risk of an exchange seem, for some, like the lesser of two evils.

The long-term impact on the hardware wallet market and user trust remains to be seen.

A difficult lesson for the self-custody landscape

The Coldcard hack serves as a stark and costly reminder that no security solution is infallible. The promise of hardware wallets is the isolation of private keys from insecure, internet-connected environments like laptops and smartphones. They are designed to be a black box for signing transactions, ensuring keys never leave the device.

However, this incident proves that the integrity of the software running within that black box is just as important as the physical isolation it provides. A flaw in the firmware can be just as devastating as a virus on a PC. It shifts the trust assumption from just the hardware to the entire software supply chain and the diligence of the manufacturer’s developers.

For the broader industry, this event will likely trigger a renewed focus on firmware verification, open-source auditing, and the importance of truly random number generation. It highlights the immense responsibility placed on manufacturers of security hardware and the catastrophic consequences when that trust is broken, even unintentionally.

As the final losses are tallied, the lessons from this expensive failure will reverberate through the crypto security space for years to come.

bitcoin theft coinkite vulnerability coldcard hack losses galaxy research report hardware wallet security
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Crypto Exchange Fees Reveal Who Really Pays for the Trade

September 9, 2026

Shiba Inu tumbles 16% as tariff war fears drive selling pressure

August 24, 2026

XRP ETF inflows surge to $40M in best week since May

August 23, 2026

Utorg launches Utapp crypto wallet and card for iOS with self-custody focus

August 22, 2026

Recent Posts

  • MoneyGram Launches First Stablecoin-Backed Visa Card in Colombia
  • BTCC Exchange Launches TOKEN2049 Trading Competition with $1M Prize Pool
  • Nasdaq, Boerse Stuttgart Ask EU to Adjust Tokenization Trial Cap
  • Zuckerberg: AI Boom Exists, But Not Necessarily a Bubble
  • Researchers Cut Bitcoin, Ethereum Quantum Attack Estimate by 50%
Top Posts

Crypto Exchange Fees Reveal Who Really Pays for the Trade

September 9, 2026

Shiba Inu tumbles 16% as tariff war fears drive selling pressure

August 24, 2026

XRP ETF inflows surge to $40M in best week since May

August 23, 2026

Stay updated with the latest crypto news, market trends, and expert insights. We provide accurate and timely information to help you make better decisions.

Facebook X (Twitter) Instagram Pinterest YouTube
Our Resources
  • About Us
  • Privacy Policy
  • Editorial Policy
  • Legal Disclaimer
  • Contact us
Categories
  • Altcoins
  • Prediction
  • Opinion
  • Guides
  • Reviews
  • Bitcoin
  • Ethereum
Recent Posts
  • MoneyGram Launches First Stablecoin-Backed Visa Card in Colombia
  • BTCC Exchange Launches TOKEN2049 Trading Competition with $1M Prize Pool
  • Nasdaq, Boerse Stuttgart Ask EU to Adjust Tokenization Trial Cap
  • Zuckerberg: AI Boom Exists, But Not Necessarily a Bubble
© 2026 Daily Crypto News

Type above and press Enter to search. Press Esc to cancel.