Coinkite confirmed that the vulnerability affected a wide range of Coldcard models running specific firmware versions:
The attacker struck in at least three waves beginning around July 30, 2026, draining funds from more than 4,500 addresses . One particularly aggressive wave saw 594 BTC stolen in just 25 minutes
. Early estimates from Galaxy Research pegged losses at roughly $70 million, but as more compromised addresses were identified, later reports converged on ~$89 million to $116 million depending on the Bitcoin price at time of reporting
.
No physical access, phishing, or malware was required — the attacker reconstructed private keys entirely from outside by predicting the weakened seed phrases .
The Coldcard hack triggered a clear split in investor behavior, visible in on-chain data from Santiment.
Bitcoin whales — wallets holding between 10 and 10,000 BTC — added 19,610 BTC to their combined holdings between July 29 and early August, a 0.14% increase worth roughly $1.25 billion at prevailing prices . Other reports placed the accumulation at 19,696 to 19,700 BTC over an eight-day window ending in late July
. This signaled "smart money" conviction that the selloff was an overreaction.
Smaller retail investors did the opposite. Wallets holding less than 0.01 BTC reduced their balances by 0.55% in the same period . Spot BTC trading volume fell 75% as retail dip-buying activity cooled
. Panic-selling by smaller holders was described as reaching levels not seen since the FTX collapse in November 2022
.
The Coldcard hack did not occur in isolation. It landed against the backdrop of a grim first half of 2026 for crypto security:
Because Coldcard was widely regarded as a gold standard for cold storage, the revelation that a silent firmware bug had compromised key generation for over five years without detection shattered confidence in hardware wallet safety. Security researchers and exchanges issued urgent warnings for all Coldcard users to rotate their seed phrases and migrate funds to new wallets . The incident reignited a critical debate: whether even air-gapped hardware wallets are sufficient when the supply-chain and firmware integrity chain can be broken by a single coding error.