NewsCryptoColdcard Firmware Flaw Drains Over $130 Million in Bitcoin as Attackers Launder Funds Through Mixers

Coldcard Firmware Flaw Drains Over $130 Million in Bitcoin as Attackers Launder Funds Through Mixers

Author: Coincentral·

Key Takeaways

  • The Coldcard vulnerability began with a March 2021 firmware bug that weakened seed randomness on affected devices.
  • Galaxy Digital said at least three attack waves drained funds from 7,300 victim wallets, with a possible fourth wave still under review.
  • Lookonchain reported that the main attacker moved 30.185 BTC, worth about $1.94 million, to a new wallet on August 7, 2026.
  • Glassnode said Bitcoin active addresses rose to about 980,000 per day after the exploit, the highest level since December 2024.
  • CertiK and TRM Labs said stolen funds were moved through mixing services and that at least 15 separate attackers have exploited the flaw.
Coldcard Firmware Flaw Drains Over $130 Million in Bitcoin as Attackers Launder Funds Through Mixers

A firmware vulnerability in Coldcard hardware wallets has triggered one of the most significant Bitcoin security incidents of 2026, with losses now estimated at over $130 million.

According to on-chain analytics, the attacker responsible for stealing 2,055 BTC (approximately $130 million) has resumed activity. Blockchain investigator Lookonchain reported on August 7, 2026:

The #Coldcard hacker, who stole 2,055 $BTC ($130M), is active again. An hour ago, the hacker transferred 30.185 $BTC ($1.94M) to a new wallet. pic.twitter.com/VTL5UB9xgH
— Lookonchain (@lookonchain) August 7, 2026

The root vulnerability traces back to March 2021, when a firmware bug degraded the randomness of seed generation on affected Coldcard devices. This reduced cryptographic key strength from 128 bits to approximately 40 bits, rendering wallets vulnerable to brute-force attacks without any physical access to the hardware. At 40 bits, the keyspace shrinks by a factor of trillions compared to the intended 128-bit security, putting affected wallets within reach of commodity computing hardware. Coldcard, manufactured by Coinkite, is widely used among Bitcoin self-custody advocates for its air-gapped design, making the randomness flaw particularly consequential for users who selected the device specifically for its security properties.

Galaxy Digital confirmed at least three waves of attacks that collectively drained funds from 7,300 victim wallets. A suspected fourth wave could increase total losses further.

Bitcoin On-Chain Activity Surges

Blockchain analytics firm Glassnode reported that Bitcoin active addresses surged to approximately 980,000 per day following the exploit—the highest level since December 2024. Glassnode emphasized that the spike reflected defensive action rather than bullish sentiment, describing it as "an operational security response, not a change in market conviction."

Dormant Bitcoin valued at nearly 200 times the initially stolen amount moved across the network, indicating widespread precautionary relocations by holders.

The catalyst for the broader on-chain response was the July 31 theft of 594 Bitcoin, valued at approximately $38 million at the time. Galaxy Research subsequently confirmed that total losses had exceeded 1,596 Bitcoin, worth more than $100 million. The more than five-year window between the firmware bug's introduction in March 2021 and the first reported exploitation in mid-2026 underscores the difficulty of detecting subtle cryptographic weaknesses in widely used hardware, even within a community that emphasizes open-source verification.

Attackers Route Funds Through Mixing Services

Blockchain security firm CertiK tracked the movement of stolen assets. Approximately 64 Bitcoin, worth $4.17 million, was sent to Wasabi, a Bitcoin mixing protocol. Separately, 200 Ether valued at around $380,000 was routed to Tornado Cash. CertiK provided details via X:

#CertiKInsight 🚨 Our alert system detected two 200 ETH transactions sent to Tornado Cash linked to the ongoing @COLDCARDwallet attack. The funds were bridged from BTC to ETH address 0x41B7529a411EeA979a8d468bdEBd36b0ad703268 via THORChain before being sent to Tornado Cash. pic.twitter.com/JLazHWIEvo
— CertiK Alert (@CertiKAlert) August 5, 2026

CertiK suggested that some of these transfers may have originated from copycat attackers. A CertiK spokesperson stated: "We think it might be a smaller exploiter. There's likely a few copycats after the initial exploit."

TRM Labs confirmed that the majority of stolen funds remain concentrated in a small number of attacker-controlled wallets. The structural differences across attack waves indicate that at least 15 separate attackers have exploited the vulnerability. The proliferation of independent exploiters from a single flaw illustrates how a latent cryptographic weakness can become a cascading threat once publicly discoverable.

Dragonfly managing partner Haseeb Qureshi noted that some AI models reportedly rediscovered the underlying vulnerability in under 20 minutes. He suggested that approximately two dollars' worth of AI-based hardening could have prevented the exploit entirely.

Security experts warn that updating firmware alone is insufficient for affected users. Anyone who generated a wallet on a compromised device is advised to create an entirely new wallet on a secure device and transfer all funds immediately.

The Coldcard exploit currently ranks as the third-largest cryptocurrency hack of 2026.