Timeline
- 8.5
Coldcard Wallet Losses Reportedly Exceed $115 Million
Reports indicate that losses tied to Coldcard hardware wallets have now exceeded $115 million. This follows a previously identified firmware flaw that weakens wallet seed generation across multiple models. This is a significant security incident for hardware wallet users, as Coldcard is widely regarded as a high-security Bitcoin-only wallet. The scale of losses could undermine trust in hardware wallet self-custody solutions and prompt a broader review of seed generation processes. The Hacker News reports a Coldcard firmware flaw that weakens seed generation across five models, with Galaxy linking a 1,196-address sweep of $70.2 million to the bug. The total reported losses exceed $115 million, suggesting additional exploits or incidents may be included.
- 9.0
Coldcard Firmware Bug Goes Unnoticed for Years, Enabling ~$100M Bitcoin Theft
A long-dormant bug in Coldcard's firmware, present since version 4.0.1 released in March 2021, led to the theft of roughly $100 million in Bitcoin on July 30, 2026. Galaxy Research tied the sweep to weak randomness in seed generation, and independent analysts later put losses as high as $116 million. Coldcard is one of the most trusted Bitcoin-only hardware wallets, yet a years-long flaw in its key-generation path validates the industry's 'don't trust, verify' maxim—as Foundation CEO Zach Herbert put it, reputation is not a security model. The incident may push users to demand stronger verification of hardware wallets and to reassess self-custody risks. The bug affected only some devices, causing generated seed phrases to have far weaker entropy than intended, and the coins swept by the attacker spanned 2021 to 2026. On July 30, about 1,196 addresses were drained in 41 minutes, taking 1,082.65 BTC; Coinkite's CEO initially denied a wallet-wide vulnerability, and attacks were reported to still be ongoing.
- 8.5
Coldcard Bitcoin Thefts Slow, But Losses Could Hit $150M: Galaxy
Galaxy Research reports the Coldcard seed-recreation exploit has stolen more than 1,778 BTC (~$112 million) and may have a fourth wave that lifts losses above $150 million. The attack waves have slowed, with no confirmed attacker activity after August 6. This is one of the largest hardware-wallet exploits on record, directly affecting Coldcard single-signature users and undermining trust in physical cold-storage devices. It also highlights how a single firmware regression in randomness can expose millions in Bitcoin years later. Galaxy identifies three major attack waves and 41 smaller footprints, with more than 5,200 addresses drained; Wave 1 alone took 1,082.65 BTC. A candidate fourth wave of 638.5 BTC has not yet been confirmed, and roughly 1,531 BTC remains unmoved in attacker-controlled addresses, with 246 BTC traced to Coinjoin transactions.
- 8.5
Coldcard Hack Spurs $15B Bitcoin Migration to Self-Custody
A Coldcard firmware exploit that began July 30 drained roughly 2,100 BTC (~$130 million), and onchain data shows 233,000 BTC (~$15 billion) moved out of long-term holder wallets in the following days. Casa CEO Nick Neuman attributes part of that migration to Ledger and Trezor users upgrading to multisig self-custody. The incident underscores that hardware wallet vulnerabilities can be contained by distributed self-custody, and may accelerate multisig adoption among long-term Bitcoin holders. It also shows self-custody adapting under stress, reinforcing Bitcoin's resilience as an asset. Checkonchain data shows 233,000 BTC left long-term holder wallets—a 1.38% drop from recent highs—while 22,000 BTC moved to exchanges. Galaxy Research separately counted roughly 1,596 BTC stolen across more than 5,200 addresses in three attack waves, and the firmware bug had reduced key entropy from 128 bits to about 40 bits.