A critical firmware vulnerability in Coldcard hardware wallets has resulted in the theft of over $130 million in Bitcoin, marking the third-largest crypto hack so far in 2026. Hardware wallet
A critical firmware vulnerability in Coldcard hardware wallets has resulted in the theft of over $130 million in Bitcoin, marking the third-largest crypto hack so far in 2026.
Hardware wallets compromised by weak key generation
Coldcard, a widely used Bitcoin hardware wallet developed by Coinkite, fell victim to a significant security lapse introduced in March 2021. Researchers found that a firmware update weakened the randomness of seed phrase generation within affected devices. This flaw diminished the cryptographic strength of wallet keys from 128 bits to just 40 bits, allowing attackers to exploit the deficiency using brute force attacks—no physical device access required.
According to an analysis by Galaxy Digital, the exploit has been leveraged in at least three separate attack waves, impacting around 7,300 wallets. The company also warned of indications that a fourth coordinated campaign may now be under way, raising concerns about potential further losses.
The breach represents one of the most severe cryptocurrency software incidents of the year, with losses continuing to mount as new attacks come to light.
Mini dictionary: Coldcard is a dedicated hardware wallet for securely generating, storing, and managing Bitcoin private keys and transactions, manufactured by Coinkite, a company specializing in Bitcoin security products.
Network activity surges as users respond
Blockchain analytics provider Glassnode reported that Bitcoin daily active addresses surged to nearly 980,000, reaching their highest level since December 2024. This surge appears linked to widespread user efforts to secure funds following news of the vulnerability, with large holders and regular users alike moving their Bitcoin to safer wallets out of precaution. Glassnode noted that the elevated transaction volume reflects operational security measures rather than renewed market enthusiasm.
Significant sums have moved across the Bitcoin network, including funds from previously inactive wallets. Analysts observed that dormant holdings totaling nearly 200 times the value of the initial theft changed hands as security concerns swept through the user base.
One major incident on July 31 saw 594 Bitcoin, worth about $38 million at the time, stolen in a single attack. Galaxy Research later confirmed that the total value lost had exceeded 1,596 Bitcoin, with the financial toll climbing as coordinated theft campaigns evolved.
Attack waveWallets compromisedTotal BTC stolenDate (where known)First to thirdApprox. 7,300Over 1,596 BTCOngoing 2024–2026Fourth (suspected)UnknownLosses increasing2026
CertiK, a blockchain security firm, recorded the movement of sizeable portions of stolen Bitcoin to mixing services designed to obscure transaction trails. At least 64 Bitcoin, valued at $4.17 million, was sent to Wasabi, a popular privacy mixing platform. Attackers also converted a portion of assets to Ether, routing 200 ETH (about $380,000) through Tornado Cash—a service that anonymizes blockchain transactions.
CertiK analysts stated that some of the suspect transactions may be unrelated to the main exploit group. The firm noted, “There’s likely a few copycats after the initial exploit.”
TRM Labs, another digital asset intelligence company, indicated that most stolen funds remain concentrated in a small number of attacker-controlled addresses. Investigators identified at least 15 separate hackers involved, based on differences in tactics used across the various attack waves.
Mini dictionary: Wasabi is a privacy-focused Bitcoin wallet and mixing service that uses the CoinJoin protocol to combine multiple transactions, making it difficult to trace specific payments. Tornado Cash is a decentralized Ethereum mixing protocol that allows users to hide the source and destination of their transactions.
Haseeb Qureshi, managing partner at Dragonfly, observed that automated security systems powered by artificial intelligence found the vulnerability within just 20 minutes. He emphasized that low-cost, AI-based tests could have identified the flaw, suggesting a missed opportunity for preventive action at a price of only around two dollars.
Cybersecurity professionals urgently recommend that anyone who generated a wallet using affected Coldcard hardware immediately create new wallets and transfer their funds. Simple firmware updates are not enough to address the compromised seed generation vulnerability.
Based on confirmed on-chain losses, the Coldcard incident ranks as the third-largest cryptocurrency hack of 2026, trailing only behind two major exchange breaches this year.
The post Coldcard vulnerability leads to $130 million Bitcoin theft, user activity spikes appeared first on COINTURK NEWS.