arrow back

Coldcard hacked: nearly $89 million in BTC stolen

02 Aug 2026

Coldcard hacked: nearly $89 million in BTC stolen

Coldcard owners lost 1367 BTC, and the amount stolen after the third wave of the attack rose to $88.6 million. This affected those who stored Bitcoin in self-custody, and now the main question is simple: can the coins still be saved?

Galaxy Research reported the incident on August 1, 2026. At first, analysts saw the second wave of attacks and recorded 1158.81 BTC, or about $75.1 million, stolen from 2673 addresses. They then updated the estimate: the third wave added another 207.73 BTC, and total losses rose to 1367 BTC from 4585 addresses. According to the researchers, all of these coins are still sitting unmoved on seven attacker addresses.

Why was Coldcard targeted?

The problem is not with the Bitcoin blockchain itself. It lies in the way some Coldcard devices generated seed phrases. Coinkite said the risk affects wallets where the seed was generated on vulnerable firmware without 50 independent dice rolls or without a strong unique BIP-39 passphrase. In simple terms, the keys may have been too predictable.

Block Engineering explained the technical cause even more bluntly: in the firmware, the MICROPY_HW_ENABLE_RNG parameter was set to 0, but the code checked only the macro itself, not its value. As a result, ngu.random did not use the STM32 hardware random number generator, but the deterministic Yasmarang PRNG. That is why several models could generate seeds with much weaker entropy than expected.

For users, this matters even more because of the scale. Galaxy Research says the first wave on July 30 lasted 41 minutes and took 1082.65 BTC from 1195 addresses. The second began about 27 hours later, on July 31, and lasted 3 hours 42 minutes, adding another 76.16 BTC from 1478 addresses. The sets of affected addresses did not overlap. That is why the attack looks not like a one-off hack, but like a sequential draining of a large group of wallets.

“The second wave was smaller in terms of bitcoin volume, but it covered more addresses. This is exactly the pattern you would expect from a tool that systematically brute-forces the key space,” Galaxy Research analysts noted.

What do the researchers’ and owners’ reactions show?

There are several worrying details here. First, most of the victims, according to Galaxy Research, are private Bitcoin holders. Second, most addresses had balances below 1 BTC, but most of the value was concentrated in large wallets. This is a typical trace of self-custody, not exchanges or large custodial services. Third, the 1158.66 BTC that researchers separately wrote about also remained unmoved, which is unusual for a theft of this size.

There is another important detail. Galaxy Research noted that Block engineers likely managed to identify the attacker. If that is confirmed, the chance of recovering part of the funds will be higher, but for now this is only a technical lead, not a ready-made solution. The story already resembles other cases where the problem was not the Bitcoin network, but weak randomness generation. That is exactly how the Milk Sad / CVE-2023-39910 case looked at the time.

  • The first wave of the attack, according to Galaxy Research, took place on July 30 and lasted 41 minutes.

  • The second wave began on July 31, about 27 hours later, and lasted 3 hours 42 minutes.

  • In total, 4585 addresses were affected, and 1367 BTC were stolen.

  • The estimated losses rose to $88.6 million.

  • The coins are still sitting unmoved on 7 attacker addresses.

  • Coinkite has already released an updated advisory and named the safe firmware versions: Mk2/Mk3 4.2.0+, Mk4/Mk5 Standard 5.6.0+, Q Standard 1.5.0Q+, Edge 6.6.0X / 6.6.0QX+.

What does this mean for investors?

For an ordinary Bitcoin holder, the conclusion is very simple: a hardware wallet does not protect you on its own if the seed phrase was created on weak firmware. Updating the firmware does not fix an old seed. Coinkite says directly that you need to create a new seed phrase and move your funds to it. If you stored Bitcoin in self-custody, checking the firmware version is now more important than any pretty security promises.

There is also a practical point for Ukrainian users. If, after such an incident, you decide to quickly convert BTC into hryvnia, it is better not to delay checking addresses and fees. For those who need to sell Bitcoin on Monobank, this can be a convenient way not to drag out the risk reassessment. It is also important to remember: if the seed was created on a vulnerable version, the device itself no longer guarantees protection without a full transfer of funds.

Another detail that matters for the future: Block says that for some models the potential key-reproduction space may have been very small, and for later versions it still remained limited. This means that even expensive devices cannot be trusted blindly. You need to look at the firmware version, the source of entropy, and how exactly the seed was created. Otherwise, the protection exists only on the box.

Frequently asked questions

Do I need to change the seed phrase after updating Coldcard?

Yes. Coinkite explicitly warned that a firmware update does not fix a seed phrase created on a vulnerable version. You need to create a new seed phrase and move all funds there.

Which Coldcard versions are considered safe after the patch?

According to Coinkite’s updated advisory from August 1, 2026, the safe versions are Mk2/Mk3 4.2.0+, Mk4/Mk5 Standard 5.6.0+, Q Standard 1.5.0Q+, and Edge 6.6.0X / 6.6.0QX+. It was separately noted that TAPSIGNER, OPENDIME, and SATSCARD were not affected.

Does this mean Bitcoin itself was hacked?

No. In this case, the attack did not target the Bitcoin network, but a weak point in seed phrase generation on specific devices. The blockchain was not hacked; the keys may simply have been predictable because of a firmware error.

The Coldcard situation once again showed a simple truth: in crypto, the weakest point is often not the coin itself, but the way people store access to it. If you need to quickly convert BTC into hryvnia, it is convenient to sell Bitcoin on Monobank without extra steps and long waits.

This material is not financial advice. Cryptocurrency trading involves significant risks. Part of this text was prepared with the help of artificial intelligence based on public sources and reviewed by our editorial team.