BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

The Coldcard Wallet Exploit: How a Years-Old Firmware Bug Has Led to More Than $116 Million in Bitcoin Theft

The cryptocurrency industry often emphasizes one golden rule: "Not your keys, not your coins." Hardware wallets have therefore become one of the most trusted tools for long-term Bitcoin stora

AnonymousCryptoCompass newsroom
August 5, 2026
4 min read
NEWS
The Coldcard Wallet Exploit: How a Years-Old Firmware Bug Has Led to More Than $116 Million in Bitcoin Theft
CryptoCompass editorial visual for bitcoin coverage.

The cryptocurrency industry often emphasizes one golden rule: "Not your keys, not your coins."

Hardware wallets have therefore become one of the most trusted tools for long-term Bitcoin storage, allowing users to hold their private keys offline instead of relying on centralized exchanges.

However, recent reports surrounding certain Coldcard devices demonstrate that even hardware wallets are not immune to security flaws.

According to the information currently available, attackers continue exploiting a weakness tied to wallet seeds generated on vulnerable Coldcard firmware, resulting in an estimated 1,816 BTC—worth roughly $116 million—being stolen from more than 5,200 Bitcoin addresses.

A Vulnerability That Began Years Ago

The reported issue originates from a firmware bug introduced in March 2021 that weakened the randomness used during seed generation on certain Coldcard devices.

While later firmware updates addressed the flaw for newly generated wallets, the critical issue is that existing seeds created during the affected period remain vulnerable.

In other words, updating the device alone does not automatically secure wallets generated with compromised entropy.

Multiple Waves of Attacks

Rather than a single isolated incident, the thefts have reportedly occurred in several coordinated waves.

Recent reports indicate:

  • July 30: approximately 1,082 BTC stolen from 1,196 addresses.
  • August 1: approximately 1,158 BTC affected across 2,673 addresses.
  • August 2: approximately 1,367 BTC across 4,585 addresses.
  • August 3: an additional 449 BTC reportedly swept from hundreds more addresses.

These figures suggest that the campaign has continued over several days, with attackers repeatedly identifying and draining vulnerable wallets.

Multiple Attackers Competing

One particularly unusual aspect of the incident is that it reportedly involves multiple independent attackers, rather than a single coordinated hacking group.

Research cited in public reporting suggests that numerous parties are attempting to sweep vulnerable wallets before competing attackers do.

This creates a race in which exposed wallets may be targeted almost immediately after being identified.

Why Updating Firmware Isn't Enough

Many users naturally assume that installing the latest firmware resolves the problem.

Unfortunately, the reported vulnerability affects the original seed generation process, not simply the device software currently installed.

A patched device prevents future vulnerable seed creation, but it cannot retroactively strengthen an already-generated seed.

For users whose wallets were created during the affected period, the recommended mitigation is:

  • Update the device firmware.
  • Generate a completely new wallet seed using the patched firmware.
  • Securely back up the new recovery phrase.
  • Transfer all existing funds to addresses derived from the new seed.

Who Appears to Be Protected?

Not every Coldcard user is necessarily affected.

According to the available reports, users who generated wallet entropy using 50 or more manual dice rolls or protected their wallets with a sufficiently strong BIP-39 passphrase are generally considered resistant to this specific attack.

However, users who relied solely on the vulnerable firmware-generated entropy during the affected period may remain exposed until their funds are migrated.

Lessons for Self-Custody

Incidents like this serve as an important reminder that self-custody is about far more than purchasing a hardware wallet.

Users should also:

  • Keep firmware updated.
  • Follow vendor security advisories.
  • Understand how recovery seeds are generated.
  • Periodically review whether older wallets remain protected under current security standards.

Hardware wallets remain one of the strongest security tools available for cryptocurrency storage, but no system is immune to implementation mistakes.

Final Thoughts

The reported Coldcard exploit illustrates an uncomfortable reality within cybersecurity: vulnerabilities can remain dormant for years before attackers begin exploiting them at scale.

For users potentially affected by the vulnerable seed-generation period, acting quickly may be the difference between retaining full control of their Bitcoin and becoming another victim.

The broader lesson extends beyond one manufacturer.

In crypto, true security depends not only on the device you choose—but also on understanding how your keys were created, protected, and maintained over time.