Coldcard Hardware Wallet Flaw Drives Bitcoin Losses Toward $110M as Fourth Attack Wave Strikes
Key Takeaways
- •A firmware bug in Coldcard Mk3 devices caused some wallets to use a predictable software-based random number generator instead of secure hardware entropy, allowing attackers to reconstruct recovery phrases remotely.
- •Approximately 5,000 wallets have been drained of more than 1,755 BTC, valued at roughly $110 million, across at least four coordinated attack waves since July 30.
- •The vulnerability specifically affects Coldcard Mk3 firmware versions 4.0.1 through 4.1.9, while Mk4, Q, and Mk5 models are reportedly not impacted.
- •Coinkite has released emergency firmware to prevent the flaw in newly generated wallets but warns that seeds already created on vulnerable firmware remain exposed and cannot be repaired.
- •The incident demonstrates that even air-gapped hardware wallets depend on software integrity at the point of key creation, leaving funds exposed indefinitely when that process fails.

A security vulnerability in Coldcard, one of the cryptocurrency industry's most widely trusted hardware wallets, has escalated into a rapidly unfolding multi-day theft campaign. Losses are now approaching $110 million in bitcoin, with a new wave of attacks reportedly underway as of publication.
The incident ranks among the largest known losses tied to a hardware wallet vulnerability. It continues to grow in real time, raising renewed questions about whether offline cryptocurrency storage can adequately protect users when the software responsible for generating wallet keys fails.
Losses Climb Past $89M as a Fourth Wave Hits
Galaxy Research detected the first wave of suspicious transactions on July 30, when attackers moved more than 1,000 bitcoin from nearly 1,200 wallets in under an hour.
Three subsequent waves have followed. By Monday, more than 1,755 BTC — worth roughly $110 million — had been drained from approximately 5,000 wallets, according to Galaxy Research.
The attack is not over. Galaxy Research's head of research, Alex Thorn, warned late Sunday that hackers may have launched a fourth coordinated attack, with a fresh wave pilfering 388.93 BTC — worth $24.53 million — from 462 addresses across 218 transactions.
🚨 LIKELY 4TH ORGANIZED WAVE COLDCARD ATTACK OCCURRING RIGHT NOW THERE ARE STILL SIMILAR TXS IN THE MEMPOOL WAITING TO BE CONFIRMED AND THE PREVIOUSLY-CONFIRMED TXS SIGNAL RBF OPT-IN, CHECK YOUR FUNDS AND YOU MAY BE ABLE TO RBF YOUR WAY OUT OF THIS pattern identified: blocks… — Alex Thorn (@intangiblecoins) August 3, 2026
Thorn measured the sweep rate during this wave at roughly 45 times the pre-incident baseline, describing it as the fingerprint of an automated pipeline working through a pre-computed list of vulnerable keys against the live mempool. The coordinated, multi-wave nature of the drain suggests the attacker or attackers pre-computed vulnerable seeds in advance and are executing sweeps as Bitcoin blocks confirm.
Firmware Error Undermined Wallet Security
According to a security advisory from Block's Bitcoin Engineering and Security team, a firmware bug affected how Coldcard generated wallet recovery phrases.
A coding error caused some devices to use a weaker software-based random number generator instead of the device's built-in hardware randomness system. Because the fallback method relied on predictable device information and timing data rather than secure random values, attackers could potentially reconstruct affected wallet seeds.
Random number generation failures are a well-documented vulnerability class in cryptocurrency. When entropy sources are predictable, the resulting keys can be brute-forced. Previous incidents across the broader crypto ecosystem — including weaknesses in certain Android wallet implementations in 2013 — demonstrated that insufficient randomness during key creation can expose funds to theft long after wallets are set up, with no subsequent physical compromise required.
Older Coldcard Wallets Are the Primary Target
The flaw was introduced in a March 2021 firmware release and affected certain Coldcard Mk3 versions, including firmware versions 4.0.1 through 4.1.9, as well as earlier releases.
COLDCARD Mk3 Security Advisory If you generated a seed on a Mk3 after firmware 4.0.1, your funds may be at risk. Mk4, Q and Mk5 are not affected based on our early analysis. Read the advisory and migrate carefully: — COLDCARD (@COLDCARDwallet) July 30, 2026
Coinkite, the company behind Coldcard, released emergency firmware to prevent the issue from affecting newly generated wallets but has warned that the update does not repair seeds already created on vulnerable firmware. The weakened recovery phrases could, under certain circumstances, be predictable enough for sophisticated attackers to reconstruct without physically accessing the device.
Coinkite noted that wallets set up using at least 50 private dice rolls for manual entropy generation bypass this flaw and are not affected.
Coldcard Tells Users to Move Their Bitcoin
Coinkite CEO Rodolfo Novak publicly apologized after the company confirmed the vulnerability, saying the company was "heartbroken" and taking responsibility for the failure. Coinkite said it disclosed the issue because attackers may still be targeting vulnerable wallets.
Because the flaw affects the recovery phrase rather than the physical Coldcard device itself, updating the hardware alone will not protect affected users. Coinkite is urging customers to install the latest emergency firmware update, create a new recovery phrase only after the update is complete, and move their bitcoin to a newly generated wallet address. Restoring an old recovery phrase on another device will not resolve the vulnerability.
Broader Implications
The Coldcard vulnerability affected the wallet creation process itself, potentially allowing attackers to access bitcoin without ever obtaining the physical device. This is notable because Coldcard is specifically designed for air-gapped operation, communicating with host machines only via SD card or NFC rather than USB — a physical security model intended to prevent remote key compromise. The fact that the flaw bypasses the device's air-gapped protections entirely, by weakening seeds at the point of creation, underscores that even robust hardware isolation cannot compensate for failures in the software that generates the keys.
The incident highlights a fundamental risk in cryptocurrency security: even devices designed to keep assets offline depend on software that must generate and protect access keys correctly. As the current attacks demonstrate, funds in wallets created years ago on vulnerable firmware remain exposed indefinitely, with no mechanism to alert affected users before their bitcoin is moved.