Coldcard-Generated Bitcoin Wallet Losses Surpass $100 Million
Key Takeaways
- •Galaxy Research said the confirmed thefts total more than $100 million, or about 1,596 bitcoin, taken from roughly 7,300 addresses.
- •The firm linked the incident to a flaw in Coldcard’s seed-generation process that reduced randomness and exposed wallets to key reconstruction.
- •Researchers said the attacks unfolded in three coordinated waves plus 14 smaller incidents, with a suspected fourth wave potentially pushing losses to about $130 million.
- •The exploit did not depend on phishing, malware, or users revealing recovery phrases, but on weak seed phrases generated by affected devices.
- •Galaxy Research said about 90% of the stolen bitcoin had not been moved and warned that the exploit remains active.

Confirmed losses from an ongoing theft targeting vulnerable Coldcard-generated Bitcoin wallets have surpassed $100 million, according to blockchain researchers who identified three coordinated attack waves and 14 smaller incidents that have drained about 1,596 bitcoin from roughly 7,300 addresses.
Galaxy Research said the thefts stem from a flaw in Coldcard’s seed-generation process that weakened the randomness used to create wallet recovery phrases, allowing attackers to reconstruct private keys without compromising the hardware devices themselves. The firm said it has “high confidence” in the confirmed losses, while a suspected fourth wave could lift the total stolen funds to about 2,055 bitcoin, or roughly $130 million.
The attack has developed rapidly since it was first detected on July 30, 2026, when about $38 million was believed to have been stolen.
BITCOIN | ~500 Bitcoin Hardware Wallet Addresses Get Drained of ~$40 Million
Estimates later rose to around $70 million after the first major sweep, climbed to nearly $89 million following a third wave over the weekend, and have now exceeded $100 million as additional victims and smaller attack clusters were identified.
CASE STUDY | Bitcoin Cold Wallet Exploit Spreads to Over 4,500 Addresses as Losses Climb to ~$90 Million
Unlike most crypto wallet compromises, the incident did not rely on phishing, malware, or users exposing their recovery phrases. Instead, attackers exploited a firmware bug that reduced the entropy used to generate wallet seeds, making certain wallets created on affected Coldcard devices mathematically predictable years after they were generated. That has renewed scrutiny of hardware wallet security, since devices designed to protect private keys can still become exposed if the seed-generation process is flawed, and it has prompted urgent warnings for affected users to move funds to newly generated wallets.
CASE STUDY | Why This Cold Wallet Exploit Exposes a Big Bitcoin Hardware Security Vulnerability
The incident challenges one of Bitcoin’s core security assumptions: that hardware wallets provide strong protection as long as users keep their recovery phrases offline. In this case, the wallets themselves generated weak seed phrases, rendering even properly stored devices vulnerable years after they were created.
Galaxy Research said 90% of the stolen bitcoin had not been moved at the time of writing. The firm continues to monitor blockchain activity and warned that the exploit remains active and that additional vulnerable wallets could still be targeted.
MILESTONE | ColdCard Hack Triggers Largest Small Bitcoin Transfer Surge Since FTX Collapse