Coldcard Bitcoin Hack Losses Top $115 Million, Galaxy Research Says
Key Takeaways
- •Galaxy Research reports that Coldcard theft losses have surpassed $115 million in bitcoin, based on prices at the time coins were stolen, and the total could exceed $130 million.
- •A firmware bug introduced in Coldcard Mk3 version 4.0.1 in March 2021 caused seed generation to fall back to a weak software pseudorandom number generator, enabling attackers to guess victims' seedphrases.
- •Galaxy Research estimates at least 15 separate attackers exploited the vulnerability independently, and the firm has spoken with more than 200 victims to support them and gather intelligence.
- •Research found the typical stolen coin had sat untouched for 3.5 years and 88% of pilfered funds were at least a year old, indicating weakly generated seeds remain guessable as long as funds sit on them.
- •Coinkite said the bug went unnoticed and its potential impact grew with each release, urging users to update software or move funds, while some investors have shifted coins to exchanges and other storage solutions.

Losses from the Coldcard hardware wallet theft have surpassed $115 million in bitcoin, according to new figures from Galaxy Research.
Writing on X on Sunday, Galaxy Research said it had spoken with more than 200 victims in order to support them and gather intelligence on the attackers. The firm noted that its loss figures are based on the price of bitcoin at the time of the attack.
Coldcard losses have exceeded $115M (based on the price when coins were stolen)
Galaxy Research has spoken with 200+ victims to support them and gather intelligence on the attackers
This thread contains additional charts and info pic.twitter.com/H2K141mugF
— Galaxy Research (@glxyresearch) August 16, 2026
Hackers began taking bitcoin stored on Coinkite's popular Coldcard hardware wallet on July 31. The Canadian company said a firmware bug in Coldcard Mk3 devices — introduced with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software pseudorandom number generator instead of the hardware true random number generator, allowing attackers to essentially guess investors' seedphrases — the recovery words that control access to a bitcoin wallet. Strong randomness is a foundation of hardware-wallet security: devices like the Coldcard are built to generate and store private keys offline, so a predictable seed defeats the secure key generation the device is designed around. Randomness failures have hit bitcoin holders before — in 2013, a weakness in Android's random number generator left keys in some Android wallet apps predictable, prompting warnings for users to move their coins.
The loss total has risen steadily as criminals have targeted more recent devices, while Coinkite and other Bitcoiners have urged Coldcard users to immediately move their funds.
Last week, Galaxy Research estimated that at least 15 separate attackers were exploiting the bug independently. Previous research from the firm found that the typical stolen coin had sat untouched for 3.5 years, and that a striking 88% of pilfered funds were at least a year old — a reminder that a weakly generated seed does not age out of risk; it remains guessable for as long as the funds sit on it. Galaxy Research is still confirming how much has been stolen, and has said that total losses could exceed $130 million.
Since the attack, cautious investors have been moving their coins to other storage solutions, including exchanges — a notable shift for holders of a device whose core purpose is self-custody, keeping bitcoin under users' own control rather than with a third party.
In a statement this week, Coinkite said the bug in its software "silently went unnoticed" and that "its potential impact grew with every release" of its products. Days after the first hack, the company urged investors to update their software or move their funds off the popular hardware wallet.
This article first appeared on Bitcoin Magazine and is written by Mathew Di Salvo. Source: Bitcoin Magazine