Coldcard Bitcoin Wallet Firmware Flaw Triggers Fourth Wave of Thefts, Galaxy Research Reports
Key Takeaways
- •A March 2021 firmware update caused Coldcard devices to use a weaker software random number generator instead of the intended hardware source, reducing entropy and potentially allowing attackers to reconstruct private keys.
- •Galaxy Research estimates that approximately 1,815 Bitcoin has been stolen across four coordinated attack waves from 5,294 suspected victim addresses, though these figures have not been independently confirmed by Coinkite or law enforcement.
- •Affected hardware models include the Mk2, Mk3, Mk4, Mk5, and Q, and users with seeds created on compromised firmware must generate entirely new wallets since the patch does not retroactively secure existing keys.
- •Seeds created with at least 50 manual dice rolls or those protected by a strong passphrase are not considered vulnerable to this specific flaw.
- •Coinkite has halted all device shipments, destroyed unsold units carrying the flawed firmware, and stated its legal team will coordinate with law enforcement agencies across multiple countries as the investigation continues.

Coldcard, a manufacturer of Bitcoin hardware wallets operated by Coinkite, is confronting a series of thefts linked to a firmware vulnerability that went undetected for approximately five years. Coldcard devices are widely used among Bitcoin self-custody advocates for their air-gapped design and support for features like dice-based seed generation, making the scope of the vulnerability particularly significant within that community. Blockchain research firm Galaxy Research reports that a fourth wave of attacks struck over the weekend, moving 448.7 Bitcoin from 709 suspected victim addresses.
Alex Thorn, Galaxy's head of research, described the affected addresses as "likely Coldcard victims" based on observed transaction patterns rather than confirmed device records. Across all four attack waves, Galaxy estimates that approximately 1,815 Bitcoin has been stolen from 5,294 addresses. This figure has not been independently confirmed by Coinkite, law enforcement, or all affected wallet owners, and it assumes no overlap among victim groups across the separate waves.
Thorn issued a public alert on X (Twitter) on August 3, 2026:
LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS pattern identified: blocks…
— Alex Thorn (@intangiblecoins) August 3, 2026
https://x.com/intangiblecoins/status/2084079706320646300?ref_src=twsrc%5Etfw
How the Vulnerability Originated
Coinkite attributed the flaw to a March 2021 firmware update that modified the device's cryptographic library. The update inadvertently routed seed creation through a weaker, software-based random number generator rather than the hardware random number generator that the device was designed to use. The quality of random number generation is foundational to hardware wallet security: if an attacker can narrow the range of possible entropy values used during seed creation, they can reduce the keyspace and potentially reconstruct private keys for affected wallets. Coinkite stated in its report that the weaker generator existed within the source code without the development team's knowledge that it was being invoked.
Affected hardware models include the Mk2, Mk3, Mk4, Mk5, and Q, each of which experienced a different degree of entropy reduction as a result of the flaw.
Block's engineering team conducted an independent review and confirmed that the firmware was calling the weaker fallback generator instead of the intended hardware source. Block noted that it had not completed full exploitation tests but agreed that early disclosure was warranted given the active theft reports.
Steps for Affected Users
Coinkite has released patched firmware for every affected model. However, installing the update does not retroactively secure wallets that already generated seeds using the compromised random number generator.
Users with older seeds are advised to generate an entirely new seed on updated firmware, verify it with a small test transfer, and then migrate the remainder of their funds. Seeds created with at least 50 manual dice rolls, or those protected by a strong passphrase, are not considered vulnerable to this specific issue.
Galaxy Research noted that some flagged transactions remain unconfirmed in Bitcoin's mempool. This provides affected wallet owners a narrow window to attempt to preempt the attack by broadcasting a replacement transaction with a higher fee — a technique known as Replace-by-Fee (RBF). This approach only works before the original transaction is confirmed in a block, and there is no guarantee the replacement will succeed.
Industry Testing Gap
Nick Percoco, chief security officer at cryptocurrency exchange Kraken, said the case highlights a broader absence of independent testing standards for hardware wallets. He drew comparisons to certification frameworks already applied to other cryptographic devices, noting that wallet manufacturers currently lack an equivalent mechanism to verify which random number generator is operating in production firmware. Security researchers have previously identified vulnerabilities in hardware wallets from other manufacturers, but no unified certification or recurring audit standard has emerged across the industry.
Coinkite's Response
Following confirmation of the bug, Coinkite halted all device shipments and destroyed unsold units that carried the flawed firmware. The company has asked users to retain old devices rather than discard them, as they may assist in tracing stolen funds.
Coinkite also posted an update on X:
— COLDCARD (@COLDCARDwallet) August 2, 2026
https://x.com/COLDCARDwallet/status/2084051697148498394?ref_src=twsrc%5Etfw
Coinkite stated that its legal team intends to coordinate with law enforcement agencies across multiple countries as the investigation into the thefts continues.