$116 Million Stolen From Bitcoin Cold Wallets That Were Never Online. Here's What Happened.

News
On July 30, 2026, at 01:31 UTC, an attacker started sweeping Bitcoin wallets.
In 41 minutes, 1,196 addresses were drained for 1,082.65 BTC — approximately $70.2 million at the time.
The devices were cold. Disconnected. Sitting exactly where their owners left them.
By August 4, confirmed losses from the Coldcard exploit had surpassed $100 million, with a suspected fourth wave pushing estimates toward $130 million — roughly 1,816 BTC drained from more than 5,200 addresses across four separate sweeps.
This is not a phishing attack. Not a compromised exchange. Not a social engineering scam.
The attacker never touched a single device. They rebuilt the private keys remotely, from public information, and swept every wallet they could reproduce.
What Actually Broke
Every Bitcoin private key must be mathematically unpredictable. The entire security model depends on this one requirement.
A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator instead of the STM32 hardware random number generator. An attacker who could determine the device UID, timer state, and prior RNG-call history could reproduce candidate output streams offline without accessing the device.
The key generation fell through to a basic software substitute seeded from the chip's serial number and its clock registers — fixed factory metadata, not secret information.
The result: effective entropy of roughly 40 bits on the Mk3, against 128 bits required for a secure 12-word BIP-39 seed.
At 40 bits, the search space collapses from "computationally impossible for centuries" to "doable in hours on modern hardware." The attacker derived Bitcoin addresses from candidate seeds, compared them against public blockchain data, and swept every wallet in the pool.
Every transaction used an identical hardcoded fee rate of 30 satoshis per virtual byte — a 30-75x overpay — and left no change output, indicating an automated tool running through the vulnerable address pool systematically.
Critical point: Cold storage does two jobs: keeping your key offline where no attacker can reach it, and generating a key no computer can guess. The Coldcard attack broke the second job while the first held perfectly. Every drained wallet stayed offline and untouched while its seed was rebuilt on someone else's machine.
Who Is At Risk
You are potentially affected if:
- You own a Coldcard Mk2 or Mk3 — these had the lowest effective entropy (~40 bits)
- You own a Mk4, Mk5, or Q running firmware before version 5.6.0 / 1.5.0Q
- Your seed was generated between March 2021 and the firmware fix in July 2026
- You did not use at least 50 independent dice rolls during setup
- You did not use a strong, unique BIP-39 passphrase
You are likely not at risk if:
- You used 50 or more fair, independent, private dice rolls during seed generation. The dice entropy alone exceeds the broken RNG contribution — the attacker cannot reproduce your seed
- You used a strong passphrase that was never stored digitally near the device
- The pattern suggests the flaw affects single-key Coldcard seeds and not multisig setups — however, multisig using multiple Coldcard devices that shared the same vulnerable firmware is still exposed
What To Do Right Now
1. Do not send funds or interact with your wallet yet. First, establish whether you are at risk using the criteria above.
2. Install the emergency firmware first. Fixed firmware is available now from blog.coinkite.com:
- Mk4 / Mk5: update to 5.6.0 or later
- Q: update to 1.5.0Q or later
- Mk3: update to 4.2.0 or later
Installing the fix does not repair a compromised seed. It only prevents new seeds from being generated with the broken RNG.
3. Generate a completely new seed on the patched firmware. This is the only cure. A new seed generated on fixed firmware is safe.
4. Migrate carefully. Confirm a receiving address on the device screen. Send a small test amount. Wait for confirmation. Then move everything else. Do not rush — a migration error creates more immediate risk than the exploit itself.
5. If you see your funds moving in Wave 4. <cite index="38-1">Unlike earlier waves, the latest transactions appear to use Bitcoin's replace-by-fee feature — meaning victims who spot their coins in the mempool may still be able to outbid the attacker and move their funds first.</cite> Check your addresses on a block explorer now if you haven't already.
Do not type your seed phrase into any website or tool claiming to check whether you're affected. The seed stays offline. Any site asking for it is a secondary scam.
The Bigger Picture
The timing stings. Blockaid reported that crypto losses topped $1 billion in the first half of 2026, most of it from compromised keys and operational failures rather than smart contract exploits — and Coldcard fits that pattern exactly, with the exposure starting at key-generation stage.
Roughly 90% of the stolen Bitcoin has not moved — it remains traceable, and Galaxy Research is working with 73 individual victims and has supplied attacker and victim addresses to law enforcement and exchanges. Recovery is not guaranteed, but it is not impossible.
The deeper lesson is about trust in complex systems. The Coldcard is one of the most security-focused Bitcoin hardware wallets ever built. Open-source firmware. Dedicated hardware RNG. Bitcoin-only operation. And a firmware integration error in March 2021 bypassed the hardware RNG silently for five years. The same AI tools that may have helped the attacker find this bug were available to defenders — and failed to flag it.
This is not a reason to abandon self-custody. It is a reason to understand exactly what self-custody requires — including entropy verification, dice roll protocols, and the knowledge that a hardware wallet is only as secure as the firmware that generated its seed.
Stay Updated
The attack is still developing. Galaxy Research confirmed losses are still being tracked, with a potential fourth wave still under assessment as of August 4.
The Fat Pig Signals free Telegram group is posting live updates on this story as it develops — including how the market is reacting, what the security implications mean for active traders, and what to watch in the coming days.
Join the free Telegram for live updates →
If you know anyone who holds Bitcoin on a Coldcard, send them this article today. The attacker is working through the largest balances first. Smaller wallets are still in the pool.
This article is for informational purposes only. For authoritative guidance on whether your specific device is affected and how to migrate safely, refer only to the official Coinkite security advisory at blog.coinkite.com. Do not enter seed phrases into any third-party tool. This does not constitute financial or security advice.


