The attacker did not need physical access, phishing emails, or malware. By reverse-engineering the weakened entropy output, they could reconstruct victims' 12- or 24-word seed phrases remotely and drain wallets that had never been connected to the internet .
Coldcard CEO Rodolfo Novak confirmed the issue on July 30, 2026, and suggested that the vulnerability may have been discovered using AI tools capable of scanning open-source firmware for entropy weaknesses at scale .
The attack unfolded in multiple coordinated waves:
By early August, TRM Labs classified the Coldcard incident as the third-largest crypto hack of 2026 . Galaxy Research identified at least 15 separate attackers now racing to exploit any unmigrated vulnerable wallets
.
On August 7, 2026, a wallet linked to the Coldcard hacker transferred 30.185 BTC (~$1.94M) to a newly created address, according to on-chain tracker Lookonchain . This was the first movement of stolen funds since the initial exploits began.
After the August 7 transfer, approximately 98.5% of the stolen ~2,055 BTC remains untouched in the hacker's wallets . This pattern is consistent with sophisticated attackers who wait for months or years before attempting to launder large sums. Blockchain forensic firms and exchanges are tracking the addresses closely
.
Coinkite moved quickly after discovering the vulnerability on July 30:
Critical warning: Installing the patched firmware does not repair an already-compromised seed. Coinkite told all affected users to generate a new seed on patched firmware and move their coins immediately . The company also destroyed remaining inventory manufactured with vulnerable firmware and halted shipments
.