NewsCryptoAfter Coldcard Was Hacked, $15 Billion in Bitcoin Moved to Safety

After Coldcard Was Hacked, $15 Billion in Bitcoin Moved to Safety

Author: Decrypt·

Key Takeaways

  • A firmware bug present in Coldcard wallets since March 2021 reduced private key security from 128 bits to approximately 40 bits, enabling brute-force attacks on consumer hardware.
  • Attackers stole between 1,596 and 2,100 BTC valued at approximately $130 million across more than 5,200 addresses in three confirmed attack waves beginning July 30.
  • The incident prompted 233,000 BTC worth roughly $15 billion to migrate from long-term holder wallets to safer configurations, representing the largest weekly decline in long-term holder supply since December 2024.
  • Because the attacker had to compromise individual addresses rather than a single custodial pool, the incremental drain gave the broader network time to react and move funds to safety.
  • Coinkite has warned that any seed phrases generated on firmware versions 4.0.1 through 4.1.9—covering a period of over five years—should be treated as compromised and migrated immediately.
After Coldcard Was Hacked, $15 Billion in Bitcoin Moved to Safety

A massive Coldcard hardware wallet exploit that began on July 30 has resulted in approximately $130 million in stolen Bitcoin, while simultaneously triggering one of the largest self-custody migrations in the network's history, with 233,000 BTC—worth roughly $15 billion at current prices—moving out of long-term holder wallets to safer configurations.

The breach targeted Coldcard hardware wallets, physical devices manufactured by Canadian company Coinkite that store private keys entirely offline. Coldcard has been widely adopted among Bitcoin self-custody users specifically for its air-gapped design, in which transactions are signed on a device that never connects directly to the internet—a security model that makes the firmware-level key compromise particularly significant for the community that relied on it. A firmware bug introduced in March 2021 had routed key generation through a weak software random number generator instead of the device's dedicated hardware chip. This caused private keys—the secret codes that prove Bitcoin ownership and authorize transactions—to become guessable, with security collapsing from 128 bits to approximately 40 bits. At 40 bits, the keyspace is small enough that modern consumer hardware can brute-force it in practical timeframes—a class of vulnerability that has plagued cryptocurrency systems before, most notably in a 2013 Android wallet flaw that likewise produced predictable keys. The vulnerability has been described as the cryptographic equivalent of a bank vault secured by a four-digit PIN.

Galaxy Research tracked the fallout across three confirmed attack waves, with losses reaching approximately 1,596 BTC across more than 5,200 addresses. Casa CEO Nick Neuman, citing onchain data from analyst James Check of Checkonchain, reported a higher figure of approximately 2,100 BTC stolen. Because the attacker had to compromise addresses individually rather than breaching a single custodial pool, the drain occurred incrementally—giving the broader network time to react.

Neuman shared the onchain breakdown in a post on X:

The onchain metrics around the Coldcard incident reinforce how important self custody is to the resilience of Bitcoin as an asset class.

In the couple of days around the hack: - 2.1k BTC was stolen - 22k moved to exchanges - 233k moved out of long term holder wallets in on… pic.twitter.com/iewr5RvG9c

— Nick Neuman (@Nneuman) August 9, 2026

According to the Checkonchain data Neuman cited, 22,000 BTC moved to exchanges, and 233,000 BTC moved out of long-term holder wallets—defined as addresses dormant for at least 155 days, a cohort analysts monitor as a proxy for serious, long-term investors. That figure represents more than 100 times the amount attackers successfully stole.

Checkonchain also posted its own analysis of the long-term holder supply shift:

The Coldcard incident resulted in Long-Term Holder supply declining by ~233k BTC, a 1.38% fall from its recent all-time high.

With such a meaningful event, an important question is whether the emergency migration of coins has skewed the onchain metrics we use to analyse Bitcoin.… pic.twitter.com/FPVLUkUlqU

— _Checkonchain (@_checkonchain) August 7, 2026

Data from analytics firm Glassnode corroborated the scale: long-term holder supply dropped from nearly 15 million BTC to approximately 14.7 million BTC—the largest weekly decline since December 2024. This occurred while Bitcoin traded roughly 50% below its all-time high of $126,000, reached in October 2025.

Casa confirmed through actual customer conversations that the migration was not limited to Coldcard owners. Some of the 233,000 BTC came from users of Ledger and Trezor—entirely separate hardware wallet brands—who used the incident as a catalyst to upgrade to multisig setups. Multisig configurations require multiple independent keys to approve any transaction, meaning no single compromised device can drain an entire wallet. Other funds came from Coldcard users migrating directly to new, secure seeds.

"So somewhere between ~10x-100x the amount of bitcoin stolen was moved to safety as people sounded the alarm," Neuman wrote.

Neuman argued that the incident demonstrated a structural advantage of self-custody over centralized custodianship. When a centralized exchange is breached, all funds are exposed at once—a pattern seen in major exchange collapses that have collectively resulted in billions of dollars in losses over Bitcoin's history. In this case, the attacker's need to crack individual addresses created a window for the rest of the network to respond.

"This is a giant flashing neon sign showcasing the resilience that self-custody adds to the network," Neuman wrote. "If all that BTC was held at a custodian and the custodian was hacked instead, those numbers would have been flipped."

Coinkite has urged anyone who generated a seed phrase on firmware versions 4.0.1 through 4.1.9—covering March 2021 to July 2026—to treat those wallets as compromised and migrate to a new seed immediately. The more than five-year window means any keys generated during that entire period are potentially affected, significantly expanding the universe of at-risk wallets beyond those actively exploited in the July attack waves.