The flaw affected seeds generated on Coldcard Mk2, Mk3, Mk4, Mk5, and Q models running vulnerable firmware versions . Newer Mk4, Mk5, and Q models saw entropy fall to roughly 72 bits
. Attackers did not need to physically access devices or compromise any network; they simply reverse-engineered the weakened entropy and swept funds from addresses they could now predict
.
Beginning July 30, 2026, Galaxy Research identified at least three confirmed attack waves . The largest single sweep drained 1,082.65 BTC (about $70 million) from 1,196 addresses in just 41 minutes
. Chainalysis analysis revealed the attacker prioritized high-value wallets first, stealing roughly $30 million in the first 10 minutes alone
. One victim lost approximately $1.8 million in that initial sweep
.
More than 5,200 individual addresses were drained across multiple waves . Some victims lost life savings. One user reported losing 20 BTC (worth roughly $1.3 million), with accounts of people who "did everything right" yet still had their funds stolen
. Because the funds were held in self-custody, no exchange or insurer was liable—leaving victims with no recourse
.
Coinkite released emergency firmware updates on July 31 for all affected models, but warned users that installing the patch alone did not fix existing wallets. Owners had to generate entirely new wallets and migrate their funds . Any seed phrase created on vulnerable firmware remained compromised
.
The hack put cybersecurity-focused exchange-traded funds squarely on investors' radar. In the days following the breach, the First Trust NASDAQ Cybersecurity ETF (CIBR) gained about 7% and the Global X Cybersecurity ETF (BUG) rose nearly 8% . Individual cybersecurity stocks also saw movement: HACK rose 1.21%, CSCO gained 1.16%, while PANW dipped 0.39% and FTNT fell 1.25%
. Analysts noted that escalating attacks reinforce the long-term case for ETFs that track companies protecting digital infrastructure
.
The most significant market impact was an accelerated shift from self-custody to regulated custody. Spot Bitcoin ETFs saw a surge of inflows:
BlackRock's iShares Bitcoin Trust (IBIT) led the rebound, receiving $111 million on Monday and $170 million on Tuesday . Bloomberg Intelligence senior ETF analyst Eric Balchunas said the hack "strengthens the case for U.S. spot Bitcoin ETFs, especially for investors who want long-term price exposure without managing private keys"
.
The hack fundamentally undermined hardware wallets' core value proposition—the idea that "not your keys, not your coins" is inherently safer. Investors who believed their Coldcard was an un-hackable cold storage solution suddenly saw that firmware bugs can bypass physical security entirely . Analysts at CoinDesk and Cantor Fitzgerald noted the breach may push users toward professional custodians like Coinbase and BitGo, and toward regulated ETF products
.
"The read-through is second-order but we would expect that token flows to custodians and exchanges will increase following the hack," Nico Pasquariello, a digital asset specialist, said in a client note .
The hack also prompted a broader security review. The Bitcoin Red Team, a volunteer security initiative, used AI-assisted reviews that uncovered 4,962 potential issues across 390 Bitcoin-related projects, including 720 high- or critical-severity findings . More than 21% of the findings were reproduced, and several critical vulnerabilities were privately reported following the Coldcard wallet attacks
. The scope of the findings suggests that the Coldcard vulnerability was not an isolated incident but a symptom of wider security gaps across the self-custody ecosystem.