Coldcard Bitcoin Theft Surpasses $114 Million as Fourth Wave of Attacks Underway
Key Takeaways
- •Total losses from the Coldcard wallet compromise have surpassed $114 million, with a fourth wave of attacks moving approximately 389 Bitcoin worth over $29 million.
- •The vulnerability stems from a firmware bug in Coldcard Mk3 devices dating to version 4.0.1 released in March 2021, which caused seed generation to use a weak pseudorandom number generator instead of the hardware true random number generator.
- •Coinkite has acknowledged that all Coldcard models are vulnerable, destroyed its remaining inventory manufactured with the affected firmware, and suspended all product shipments.
- •Engineers at Block independently investigated the hack and found that attackers used a major blockchain services provider to help move stolen funds, prompting Block to contact both the provider and federal authorities.
- •The largest single transaction observed in the ongoing theft involved 51 Bitcoin being drained from a single address.

Hackers continue to drain funds from Coldcard Bitcoin wallets, with total losses now estimated at over $114 million, making this one of the largest hardware wallet compromises in Bitcoin's history.
A fourth wave of attacks likely began on Sunday evening, according to Alex Thorn of Galaxy Research. In a post at approximately 7:50 p.m. New York time, Thorn reported that 388.9 Bitcoin — worth more than $29 million — had been moved in new transactions assessed as highly likely to be connected to the ongoing theft.
The attacks first came to light on Thursday, when hackers stole over $35 million in Bitcoin from affected wallets. Coinkite, the manufacturer of Coldcard, attributed the vulnerability to a firmware bug in Coldcard Mk3 devices dating back to version 4.0.1, released in March 2021. The bug caused seed generation to fall back to a weak software pseudorandom number generator rather than the hardware true random number generator, effectively enabling attackers to guess users' seed phrases. Because seed phrases serve as the master key to a self-custody Bitcoin wallet — anyone who obtains them can spend the funds without the physical device — the flaw effectively bypassed the core security promise of cold storage.
The vulnerability's origin in a firmware release from early 2021 means that wallets created on affected devices over a period of years may carry compromised seeds.
The theft persisted throughout the weekend as Coinkite and other members of the Bitcoin community urged Coldcard users to move their funds immediately.
Posting on X on Monday, Josef Tětek of Trezor noted that the largest single transaction in the ongoing theft thus far involved 51 Bitcoin.
The biggest drained address (so far) is 51 BTC. Damn. Imagine owning 50+ btc in cold storage and losing it all. Must be absolutely crushing. pic.twitter.com/qu6CiQOjeV — Josef Tětek (@JosefTetek) August 3, 2026
Following additional thefts, Coinkite acknowledged that all of its models were vulnerable. Engineers have warned that every Bitcoin address associated with Coldcard could eventually be at risk.
On Sunday, the company said it was confronting "hard questions about our company."
"The last three days have been some of the hardest in this company's history, and for a lot of the people reading this, they've been something much worse," Coinkite stated. "Money that took years to save, gone. Trust that took years to build, broken. That impact is real, and for some, the damage is permanent."
Coinkite also confirmed that it had destroyed its remaining Coldcard inventory manufactured with the vulnerable firmware and that all product shipments have been halted. The company produces a range of Bitcoin products, including its widely used cold storage hardware wallets.
Engineers at the payments company Block conducted an independent investigation of the hack. They reported that the attackers utilized a major blockchain services provider to assist in moving the stolen funds. Block stated that it has contacted both the provider and federal authorities with its findings. The incident underscores a broader challenge for the hardware wallet industry, where the integrity of random number generation at the manufacturing and firmware level is critical to user security and where even air-gapped devices are only as trustworthy as the entropy underlying their seed creation.