BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Canadians Hit Hardest By $130M Coldcard Hack

Canada Bears the Biggest Share of Losses Canadian Bitcoin $BTC holders have emerged as the hardest-hit group from the ongoing Coldcard wallet exploit, accounting for 25% of total losses, the

AnonymousCryptoCompass newsroom
August 7, 2026
3 min read
NEWS
Canadians Hit Hardest By $130M Coldcard Hack
CryptoCompass editorial visual for bitcoin coverage.

Canada Bears the Biggest Share of Losses

Canadian Bitcoin $BTC holders have emerged as the hardest-hit group from the ongoing Coldcard wallet exploit, accounting for 25% of total losses, the largest share of any single country, according to Chainalysis. The concentration is not entirely surprising: Coinkite, the Toronto-based company behind Coldcard, made a bitcoin-only hardware wallet that has been the latest target of the breach. Australia follows with an estimated 15% to 20% of losses, while the US and Thailand each account for between 10% and 15%.

As of Tuesday, Galaxy Research said hackers have stolen around $130 million, a figure that Tom Robinson, co-founder of Elliptic, told TechCrunch was "roughly correct." Nearly half of that, roughly $70 million, was stolen in the first 41 minutes of the cyberattack. One detail underscores the profile of victims: the stolen coins had, on average, sat untouched for about 3.18 years before being swept, pointing to long-term holders and cold storage users who had trusted the device with funds they rarely moved.

A Five-Year-Old Firmware Flaw at the Root

Firmware version 4.0.1, which introduced the bug, was released in March 2021. Every seed generated on an affected Coldcard between March 2021 and the patched firmware releases on July 31, 2026, is potentially compromised. The firmware bug weakened seed randomness on some Coldcard wallets, cutting key strength from 128 bits to as little as 40, making them brute-forceable without physical access.

A build configuration error caused some devices to fall back on a weak software random number generator instead of the device's hardware-based entropy source when generating wallet seeds. Once attackers understood the flaw, they could mirror the same process on their own computers, enumerate possible recovery phrases, and sweep funds without ever touching the physical device.

The exploit has fragmented from a handful of coordinated waves into an open free-for-all, with Galaxy Research estimating that at least 15 separate attackers are now draining vulnerable wallets. Stolen funds are pooling at a small number of attacker-controlled addresses, with laundering activity remaining limited so far.

Coinkite acknowledged the issue in a detailed security advisory, released fixed firmware to address the problem, and provided instructions for affected users. Critically, the firmware version installed when the device created the seed determines exposure. Updating the firmware does not protect a seed that was already generated under the vulnerable version. Affected users are urged to generate an entirely new seed and migrate their funds to new addresses.

The incident is the third-largest crypto hack of 2026, bringing the year's total past $1.2 billion across 276 incidents.

Sources:TechCrunch: Hackers steal over $130M by exploiting bug in offline hardware walletsTRM Labs: Inside the Coldcard HackCoinkite: Official Coldcard Security Advisory