Ripple CTO Emeritus Decodes Coldcard Bitcoin Hack As Losses Exceed $100 Million
Highlights
- Confirmed losses from the Coldcard Bitcoin wallet hack have surpassed $100M, with Galaxy Research warning a suspected fourth wave could push totals toward $130M.
- The exploit traces to a March 2021 firmware flaw that weakened seed entropy, letting attackers pre-compute seeds and sweep 1,596 BTC across roughly 7,300 addresses.
- Coinkite has patched firmware, but users who generated seeds on vulnerable builds must move funds to a freshly generated wallet immediately, an update alone won't fix compromised seeds.
Confirmed losses from the Coldcard Bitcoin wallet hack have surpassed $100 million, with Galaxy Research now warning that a suspected fourth wave of attacks may push total losses toward $130 million. The exploit targets a firmware flaw introduced in March 2021, and it is still active.
A Five-Year-Old Firmware Bug Behind Bitcoin’s Largest Self-Custody Heist
The breach traces back to a build error in Coinkite’s firmware version 4.0.1, released around March 2021.
Affected devices, primarily Coldcard Mk2 and Mk3 models, failed to use the hardware true random number generator (TRNG) correctly during seed creation.
Instead, wallets fell back on a weaker software-based pseudorandom number generator, slashing effective entropy to as low as 40 bits on older firmware, far below the intended 128 bits. That weakness made seed phrases far easier to guess offline.
Attackers pre-computed candidate seeds, matched them to on-chain addresses holding Bitcoin, and swept single-signature wallets, without ever touching a physical device.
The first major sweep hit around July 30, 2026, draining over 1,000 BTC from more than 1,200 addresses in under an hour. Two further waves followed, targeting remaining vulnerable balances.
Galaxy Research has confirmed 1,596 BTC stolen across roughly 7,300 addresses in three waves, with approximately 14 smaller incidents recorded separately.
Galaxy Research shared around 600 suspected attacker addresses with U.S. federal investigators, crypto exchanges, and cybersecurity firms.
Notably, roughly 90% of the stolen funds across confirmed waves remain unmoved, an unusual pattern that investigators continue to monitor.
The scale of the Coldcard Bitcoin wallet hack is drawing comparisons to earlier cold-storage failures.
Just as Bybit’s $1.4B Cold Wallet Breach exposed how manipulated signing processes could bypass even multi-signature protections.
The Coldcard case shows that implementation-level errors in seed generation carry equally severe risks, regardless of whether a device is air-gapped.
What Coldcard Owners Must Do Now
Coinkite has issued security advisories, released patched firmware for all affected models, and halted shipments of vulnerable inventory.
However, the company is emphatic on one point: updating firmware alone does not fix seeds that were already generated on vulnerable builds.
Any user who generated their seed on Coldcard firmware around or before version 4.1.x must move funds immediately to a wallet created with a freshly generated seed on clean, fixed firmware.
Coinkite recommends using dice-roll entropy during setup for maximum independence from device-generated randomness.
Multi-signature setups across different wallet vendors may also have offered partial protection in some cases.
Ripple CTO Emeritus David Schwartz (@JoelKatz) weighed in on X, framing the Coldcard Bitcoin wallet hack within a broader conversation on outlier risk in crypto custody.
I guess it might be semantics and also a question of how to measure the risk because the denominators are hard to measure (and much greater for tradfi). But there were many brokerages that lost customer stock holdings in the 1970's. There was MF Global losing customer funds for…
— David 'JoelKatz' Schwartz (@JoelKatz) August 4, 2026
He drew comparisons to historic TradFi failures, including MF Global in 2011, while noting the key difference: insurance availability in traditional finance does not currently extend to self-custody crypto losses.
The incident has renewed debate about whether Hardware Wallets Are Still Safe, with security researchers pointing out that even air-gapped.
Bitcoin-only devices carry manufacturer and firmware implementation risks that users rarely account for.
Victims who lost funds can report drained addresses and transaction IDs to Galaxy Research via DM at @intangiblecoins on X.
The Bitcoin protocol itself was not affected. This was a wallet-seed generation failure, not a network-level compromise.
The broader pattern is hard to ignore. Earlier in 2026, $52M in crypto hacks triggered shadow contagion across DeFi, signaling that 2026 is shaping up as a year defined by persistent multi-vector attacks.
The Coldcard Bitcoin wallet hack adds a new dimension: this time, the attack came from inside trusted hardware.
Our guide breaks down the top crypto loan platforms offering competitive rates.











