Coldcard Attack Expands as 15 Hackers Drain $130 Million in Bitcoin
Key Takeaways
- •Galaxy Research identified at least 15 separate attackers using the Coldcard vulnerability.
- •The campaign has reportedly stolen more than $130 million in Bitcoin from over 7,300 wallets.
- •The flaw affected seed generation on Coldcard devices and produced weaker entropy than intended.
- •Coinkite has released hotfixes and warned users that the threat is still active.
- •Users are being told to update their Coldcard devices, create new seeds, and transfer funds to new wallets.

Galaxy Research has identified 15 attackers targeting vulnerable Coldcard wallets.
Estimated losses have surpassed $130 million in Bitcoin across more than 7,300 wallets.
According to Coinkite’s latest warning, the threat remains active.
The Coldcard wallet attack has escalated after Galaxy Research identified 15 separate attackers exploiting a firmware vulnerability that weakened private key generation on affected hardware wallets.
The ongoing attack has drained an estimated $130 million in Bitcoin from more than 7,300 wallets, and additional losses are possible because the vulnerability is publicly known.
Because the flaw is public, any hacker with sufficient technical skill can join the theft campaign.
Why hackers are still targeting Coldcard wallets
The Coldcard wallet attack continues because vulnerable wallet addresses remain visible on Bitcoin’s public blockchain, allowing attackers to identify affected wallets and attempt to recover private keys through brute-force methods.
Galaxy Research said dozens of victims have already contacted the firm, but the total number of affected users could be significantly higher. Some long-term Bitcoin holders may still not realize their wallets were exposed.
"now NUMEROUS different attackers exploiting the Coldcard vulnerability. we estimate at least 15 different attackers now we continue to receive victim reports and give them info to report to authorities and those reports help us identify new attacks and label attackers " — Alex Thorn (@intangiblecoins) August 4, 2026
"now NUMEROUS different attackers exploiting the Coldcard vulnerability. we estimate at least 15 different attackers now we continue to receive victim reports and give them info to report to authorities and those reports help us identify new attacks and label attackers "
The vulnerability was tied to Coldcard firmware that redirected wallet seed generation through MicroPython’s software fallback instead of a true random number generator. That weaker process produced seed phrases with significantly reduced entropy.
Coinkite, the company behind Coldcard hardware wallets, estimated that seeds generated on Coldcard Mk2 and Mk3 devices contained about 40 bits of entropy, well below the company’s 128-bit target.
Coldcard Mk4 devices reportedly generated seeds with about 72 bits of entropy, which was still below the expected security level.
Coinkite co-founder Rodolfo Novak apologized for the bug on X on July 31 and wrote that the company takes "full accountability for the firmware bug." Coinkite has since released hotfixes across every affected model and release track.
The company repeated its warning on Tuesday that "the threat is still active," urging Coldcard users to move funds to newly generated, unaffected wallets.
"🚨 URGENT: The threat is still active. Follow the advisory for your model: update your COLDCARD, generate a new seed, then carefully move your funds. Please share this with less-online users who may not see it. " — Coinkite (@Coinkite) August 4, 2026
"🚨 URGENT: The threat is still active. Follow the advisory for your model: update your COLDCARD, generate a new seed, then carefully move your funds. Please share this with less-online users who may not see it. "
As of the time of writing, the identity of the hacker or hackers has not been publicly verified.
The continuing activity underscores a practical challenge for hardware wallet users: once seed weakness is exposed and old addresses can still be traced on-chain, simply patching firmware does not remove funds already at risk. That leaves affected users dependent on moving assets to newly generated wallets using updated software, which makes Coinkite’s advisory especially important for people who may not follow security updates closely.