On July 30, 2026, attackers began draining Coldcard hardware wallets by exploiting a five year old firmware bug that reduced seed entropy to as little as 40 bits. The hack drove the highest onchain activity of 2026 and a surge of $853M into U.S.
Research answer

Create a landscape editorial hero image for this Studio Global article: What was the scale and nature of the Coldcard hardware wallet hack in 2026 — covering the estimated total losses ($100M–$130M / 1,432–1,816. Article summary: Here is a comprehensive account of the Coldcard hardware wallet breach of July–August 2026, based on reporting from Galaxy Research, TRM Labs, Forbes, Fortune, TechCrunch, The Block, Cointelegraph, and others.. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers,
On July 30, 2026, a security incident began unfolding that would become the largest-ever theft from Bitcoin hardware wallets. Over the following week, attackers drained between 1,596 and 2,055 BTC (approximately $100 million to $130 million) from Coldcard devices — wallets that were marketed as the gold standard for paranoid, air-gapped cold storage . The root cause was a single preprocessor macro error introduced into the firmware in March 2021 that silently collapsed the cryptographic randomness of seed generation from a secure 128 bits to as little as ~40 bits
. This article provides a comprehensive account of the breach, based on reporting from Galaxy Research, TRM Labs, Forbes, Fortune, TechCrunch, The Block, Cointelegraph, and others.
The attack unfolded in at least four escalating waves. The confirmed tally across the first three waves is 1,596 BTC stolen from roughly 7,300 addresses, with a suspected fourth wave that could push the total to approximately 2,000–2,055 BTC . Different blockchain analytics firms reported slightly different figures due to varying counting cutoffs and whether unconfirmed fourth-wave activity was included
:
| Source | BTC stolen | USD equivalent |
|---|---|---|
| Galaxy Research (confirmed) | ~1,596 BTC | ~$100M+ |
| Galaxy Research (incl. 4th wave) | ~2,000 BTC | ~$130M |
| TRM Labs | ~1,816 BTC | ~$116M |
| K33 | — | ~$114M |
| CryptoQuant / others | 1,432–1,367 BTC | ~$89M–$100M |
Galaxy Research identified at least 15 separate attackers exploiting the vulnerability simultaneously . Remarkably, 90% of the stolen BTC remained unmoved as of early August, with Galaxy providing attacker addresses to U.S. federal law enforcement
.
The vulnerability was a preprocessor macro error introduced in Coldcard firmware v4.0.1, released in March 2021 . A C preprocessor guard tested whether a macro was defined rather than testing its value. This caused the linker to resolve seed generation against a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (TRNG)
. The bug had sat unnoticed in open-source code for over five years
.
Entropy collapse: On Mk2 and Mk3 devices (running firmware v4.0.1 through v4.1.9), effective entropy dropped from the intended 128 bits to roughly ~40 bits . On Mk4, Mk5, and Q models, the fallback yielded about 72 bits — also below spec
. Seeds generated with ~40-bit entropy are brute-forceable without physical access to the device
.
The attack progressed with alarming speed:
All affected wallets were single-signature configurations. Multi-signature wallets were not impacted .
Coinkite released a patched firmware that restored the correct hardware RNG path for future seed generation . However, the patch cannot retroactively fix seeds already generated by compromised firmware. Users whose wallets were created between March 2021 and the patch's release were advised to immediately sweep funds to new wallets with a freshly generated seed
. The company emailed customers dating back to 2019 to warn them of the bug
and destroyed its remaining vulnerable inventory
.
Before the breach, Coinkite had a strict privacy policy of automatically deleting customer data (emails, purchase records) after 90–120 days . After the hack, the company reversed this policy, announcing it would retain customer records in preparation for anticipated legal proceedings
. This drew significant backlash from privacy-focused users who had chosen Coldcard partly for its data-minimization stance
. Coinkite stated the data would be stored with restricted access and that customers could still request standard deletion
. Thomas Braziel of 117 Partners is reportedly investigating product liability claims and a potential class-action lawsuit against Coinkite
.
The breach drove a surge in onchain activity to the highest level of 2026 as victims moved remaining funds and the broader market reassessed self-custody risk . Weekly net inflows into U.S. spot Bitcoin ETFs jumped to approximately $853 million in the week following the hack, as institutional investors rotated toward regulated custody solutions in response to the Coldcard failure
.
The Coldcard hack crystallized several uncomfortable truths for the Bitcoin self-custody community:
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
On July 30, 2026, attackers began draining Coldcard hardware wallets by exploiting a five year old firmware bug that reduced seed entropy to as little as 40 bits.
On July 30, 2026, attackers began draining Coldcard hardware wallets by exploiting a five year old firmware bug that reduced seed entropy to as little as 40 bits. The hack drove the highest onchain activity of 2026 and a surge of $853M into U.S.