Coldcard Bitcoin Theft Reaches $88.6M as Galaxy Research Identifies Third Attack Cluster
Key Takeaways
- •Galaxy Research estimates that suspected Coldcard-related thefts total 1,367.05 BTC, approximately $88.6 million, spread across 4,585 addresses.
- •A 2021 software integration erroneously routed seed generation to MicroPython's deterministic fallback random-number generator instead of the hardware RNG, reducing wallet entropy to as low as 40 bits on older models.
- •Coinkite released corrected firmware on August 1, but the patch cannot retroactively secure seeds created under the vulnerable code, requiring users to generate entirely new seeds.
- •Seeds produced using at least 50 fair, independent dice rolls or protected by a strong BIP-39 passphrase are not affected by this specific flaw.
- •Coinkite's TAPSIGNER, OPENDIME, and SATSCARD products remain unaffected because they use different codebases from Coldcard devices.

Estimated losses tied to a Coldcard seed-generation vulnerability have climbed to 1,367.05 Bitcoin, worth approximately $88.6 million, according to on-chain analysis by Galaxy Research. The updated figure follows the identification of a third suspected theft cluster. Coldcard, manufactured by Coinkite, is a widely used Bitcoin-only hardware wallet known for its air-gapped design and popularity among self-custody advocates.
A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained. Our estimated observed size of the Coldcard hack is now 1,367.05 BTC (~$88.6m) across 4,585 addresses. More updates in the thread below pic.twitter.com/g6xA4OOi2f
— Galaxy Research (@glxyresearch) August 1, 2026
The latest attack wave drained 207.7294 BTC, expanding an investigation that initially produced a much smaller estimate. Early reports placed losses near 594 BTC—then valued at roughly $38 million—across approximately 500 wallets.
Galaxy subsequently reconstructed a larger coordinated sweep of 1,082.65 BTC from 1,196 addresses, executed within a 41-minute window on July 30. Those transactions spanned six blocks, suggesting that vulnerable keys had been identified in advance before funds were moved in coordinated batches.
On-Chain Estimate Covers 4,585 Addresses
The current estimate spans 4,585 addresses. Galaxy reported that attacker-controlled endpoints held 1,366.3865 BTC that remained unspent on-chain. The firm classified the activity as suspected hacks, meaning the total represents an on-chain estimate rather than a confirmed victim-by-victim accounting.
The evolving totals underscore a common challenge in cryptocurrency theft investigations. Analysts must connect new address clusters while distinguishing victim wallets from attacker destinations and intermediate transfers—all while preventing the same funds from being counted twice. This task grows more difficult when stolen funds remain stationary, as investigators cannot rely on subsequent transfers to clarify ownership patterns. Nevertheless, the unspent balances provide a visible record of the suspected theft's overall scale.
Root Cause: Compromised Seed Randomness
The attack did not depend on physical device access, malware, or a stolen recovery phrase. Instead, the vulnerability originated at the moment affected devices generated the cryptographic seed controlling each wallet.
A 2021 software integration redirected seed creation to MicroPython's deterministic fallback random-number generator instead of the intended hardware random-number generator. This error sharply reduced the entropy protecting newly created wallets. Because the defect was introduced in 2021, seeds generated across multiple years of device usage could be affected, broadening the potential exposure window considerably.
Older Coldcard Mk2 and Mk3 units produced an estimated 40 bits of effective search space. Newer Mk4, Q, and Mk5 models reached approximately 72 bits—well below the intended 128 bits.
Engineering and security teams at Block traced the weakness to this same firmware path. Their review determined that device identifiers, timer states, and earlier generator calls could be used to narrow the range of possible seed outputs. An attacker could then reproduce candidate seed streams offline and compare derived public addresses against publicly visible blockchain records. This technique exposed wallets even when devices were kept air-gapped and backups were stored offline.
Firmware Patched, but Existing Seeds Remain Vulnerable
Coinkite, the manufacturer of Coldcard, broadened the scope of affected devices on August 1 and released corrected firmware across all impacted product lines. However, installing updated software cannot retroactively strengthen a seed that was created under the defective randomness.
Affected users are advised to generate a new seed on fixed firmware, verify the backup and receiving address, and send a small test transaction before moving the full balance. Only after confirming the test should the remaining funds be transferred.
Seeds created using at least 50 fair, independent, private dice rolls are not considered exposed by this specific flaw. A strong BIP-39 passphrase provides additional protection, though migration to a new seed remains the recommended course of action.
Coinkite's TAPSIGNER, OPENDIME, and SATSCARD products are unaffected, as they rely on different codebases. Multisignature configurations can reduce comparable risks, but only when a sufficient number of signing keys originate from independent and uncompromised sources.
The incident illustrates that while hardware isolation effectively protects secrets after they are created, it cannot remedy weak randomness at the point of generation. Random-number generation failures rank among the most consequential classes of cryptocurrency security defects because they undermine the foundational layer of private keys. In this case, the wallet's most critical vulnerability existed before its first transaction was ever signed.