NewsCryptoBlock Traces $38 Million COLDCARD Bitcoin Theft to Blockchain Services Provider

Block Traces $38 Million COLDCARD Bitcoin Theft to Blockchain Services Provider

Author: CoinTrust·

Key Takeaways

  • The July 30, 2026 exploit drained approximately 594 Bitcoin valued at around $38 million from nearly 500 COLDCARD wallets in roughly 25 minutes.
  • The vulnerability originated in COLDCARD firmware version 4.0.0, released in March 2021, which replaced the hardware random number generator with a predictable software-based process that could allow attackers to reconstruct wallet seeds.
  • The flaw primarily affected COLDCARD Mk3 devices and a limited number of Mk2 units, while newer models including the Mk4, Q, and Mk5 were not exposed to the same weakness.
  • Block and Coinkite conducted a joint investigation that connected the attacker's on-chain activity to a blockchain services provider, marking a step toward attribution though fund recovery remained uncertain.
  • Coinkite issued an urgent advisory recommending that all users with potentially affected wallet seeds create new seeds on unaffected hardware and migrate their cryptocurrency holdings immediately.
Block Traces $38 Million COLDCARD Bitcoin Theft to Blockchain Services Provider

Block's engineering team has identified the entity believed to be responsible for a major exploit targeting COLDCARD hardware wallets, tracing the attacker's on-chain activity to a blockchain services provider connected to the theft. Block, the financial technology company formerly known as Square, has maintained a dedicated focus on Bitcoin-related initiatives, including self-custody hardware through its own wallet division.

COLDCARD, manufactured by Coinkite, is a Bitcoin-only hardware wallet widely used by self-custody advocates for its air-gapped security model and transparent firmware. The device is regarded as one of the more security-focused hardware wallets available, making the scale of the breach particularly notable for the self-custody community.

The security breach took place on July 30, 2026, resulting in the loss of approximately 594 Bitcoin from nearly 500 wallets. At the time of the incident, the stolen cryptocurrency was valued at roughly $38 million. According to investigators, the attacker drained all affected wallets in approximately 25 minutes, with transactions executed between 01:31 and 01:56 UTC.

Firmware Vulnerability Dating Back to 2021

Investigators determined that the exploit stemmed from a firmware vulnerability introduced more than five years earlier. The flaw originated in COLDCARD firmware version 4.0.0, released in March 2021.

The compromised firmware disabled the hardware random number generator and substituted it with a predictable software-based process, potentially enabling attackers to reproduce wallet seeds generated on affected devices.

Hardware random number generators are designed to produce unpredictable values that secure cryptographic keys and wallet recovery phrases. Random number generation flaws have been a documented attack vector in cryptocurrency systems for over a decade; in 2013, a vulnerability in Android's secure random number generator led to the theft of funds from multiple Bitcoin wallet applications on the platform. According to the technical findings, the affected COLDCARD firmware relied on a software fallback that used non-secret seed inputs. An attacker who understood the weakness could reconstruct wallet seeds using device-specific metadata and other predictable information.

The vulnerability primarily affected COLDCARD Mk3 devices and a limited number of Mk2 units. Only wallets whose recovery seeds had been created while the affected firmware version was installed were at risk.

Evidence Suggests Years of Preparation

The investigation indicated that the attacker may have known about the vulnerability for several years before executing the theft. The wallets selected during the incident appeared to include dormant accounts, suggesting that the attacker spent considerable time identifying vulnerable devices and calculating the corresponding wallet seeds.

The short duration of the attack also pointed to extensive preparation. Engineers assessed that the attacker likely generated vulnerable wallet seeds in advance and developed automated tools to execute the withdrawals rapidly. The speed and scale of the operation suggested that the attacker had pre-computed the targeted wallet credentials and automated the transfer process.

Joint Investigation and Coordinated Disclosure

Block collaborated with Coinkite, the manufacturer of COLDCARD hardware wallets, to investigate the incident and trace the movement of stolen funds. Their analysis reportedly connected the attacker's on-chain activity to a blockchain services provider.

The joint investigation supported an urgent disclosure process before detailed technical information about the vulnerability was made public. The coordinated response was designed to reduce the risk of additional exploitation while affected users were notified.

Coinkite Advises Immediate Wallet Migration

Coinkite issued an advisory for users of COLDCARD Mk3 devices and older models whose wallet seeds may have been generated under the affected firmware versions. The company's initial assessment indicated that newer devices — including the Mk4, Q, and Mk5 models — were not exposed to the same random number generation weakness.

URGENT COLDCARD SECURITY UPDATE

Read carefully before acting.

Mk3 seed generated on 4.0.1+ without ≥50 private, independent dice rolls: begin a careful migration now.

Mk4/Mk5 <5.6.0 or Q <1.5.0Q: update first, generate a new seed, then migrate.

— COLDCARD (@COLDCARDwallet) July 31, 2026

Users potentially affected by the vulnerability were advised to create entirely new wallet seeds using unaffected hardware and transfer their cryptocurrency holdings to the newly generated wallets as soon as possible. The recommended security measure was to abandon potentially exposed recovery seeds, generate new seeds on unaffected devices, and immediately migrate all funds.

Broader Implications

The incident occurred while Bitcoin was trading above $64,000, though the theft appeared to have limited immediate impact on the broader cryptocurrency market.

The case underscored the long-term security risks associated with firmware flaws in hardware wallets, which are otherwise considered among the most secure methods for storing cryptocurrency private keys. Users who installed the March 2021 update may have believed they were strengthening their device security, but some instead generated wallet seeds through a weakened and predictable random number process.

The breach also demonstrated that vulnerabilities can remain dormant for years before being exploited — particularly when attackers have sufficient time to identify affected wallets, reconstruct sensitive credentials, and automate large-scale transactions. The identification of a connected blockchain services provider marked a step toward potential attribution, though the path to fund recovery remained unclear at the time of disclosure.