Crypto & DeFi

    The Coldcard Hack Grows to $88.6 Million and 4,585 Bitcoin Wallets Across Three Attack Waves

    Galaxy Research identified a third wave of thefts on August 1 that pushed the total to 1,367 BTC across 4,585 addresses, with none of the stolen funds moved and Binance founder CZ urging holders to split funds across wallets.

    By Aaron Rafferty·WYDE Newsroom· 3 min read
    Share
    The Coldcard Hack Grows to $88.6 Million and 4,585 Bitcoin Wallets Across Three Attack Waves

    Key Takeaways

    • An attacker drained 1,082.65 BTC in 41 minutes on July 30, and by August 1 Galaxy Research counted three attack waves totaling 1,367.05 BTC, about $88.6 million, across 4,585 Coldcard-linked addresses.

    • The cause was a firmware build setting dating to March 2021 that skipped the device's hardware randomness generator, so seed phrases were produced by a software substitute seeded from the chip's serial number and clock.

    • Coinkite, Coldcard's maker, has apologized and shipped emergency firmware, but a firmware update does not fix a seed that was already generated on the flawed code.

    The pitch for a hardware wallet has always been distance. Keep the key on a device that never touches the internet and there is nothing for an attacker to reach. A flaw in Coldcard, one of the most widely used bitcoin hardware wallets, broke that promise without going near a single device.

    Galaxy Research mapped the first sweep at 1,082.65 BTC moved between 01:10 and 01:51 UTC on July 30 from 1,196 addresses. A second wave about 27 hours later lifted the count to 1,158.66 BTC, and on August 1 the firm identified a third wave of 207.73 BTC that brings the total to 1,367.05 BTC, about $88.6 million, across 4,585 addresses. The third wave batched victims together and used new address types, which Galaxy says could mean the original attacker changed techniques or a second actor found the same flaw. None of the stolen bitcoin has moved.

    The mechanism is the story. When a wallet is created, the device is supposed to pick a number so large and so random that guessing it is impossible, and every private key derives from that seed by public rules. A build setting told Coldcard's firmware to skip the dedicated hardware randomness chip, and a supporting library only checked that the setting existed, not that it was on. Key generation fell through to a software substitute seeded from the chip's serial number and its clock. Researchers put the range of possible seeds on the Mk4, Q and Mk5 at roughly four billion.

    Coinkite CEO Rodolfo Novak took full accountability for the bug and told users to move their funds. Casa CEO Nick Neuman criticized the fallback advice that people supplement wallet randomness with physical dice rolls, calling it "a non-starter for 99% of people." Owners cannot test whether their own seed sits inside the reproducible range, so anyone who generated one on affected firmware has to assume the worst.

    Chainalysis found the attacker swept the largest wallets first, and Binance founder Changpeng Zhao urged holders to split funds across multiple wallets while the stolen coins sit untouched.

    The pattern here is hard to ignore. WYDE covered the same lesson from the other direction last week when BitMart, BitMEX and AscendEX all wound down and holders were told to self-custody. And the cost of finding flaws like this keeps falling, which is what made Anthropic's disclosure about its models breaching real systems land the same week. Storing a key safely is now the easier half of the problem.

    People Also Ask

    Which Coldcard models are affected by the seed flaw?

    Coinkite first warned owners of Mk3 devices running firmware 4.0.1 from March 2021 or later, then expanded the advisory to certain Mk4, Mk5 and Coldcard Q versions. Block's analysis places the Mk2 in scope as well.

    Does updating the firmware fix the problem?

    No. The emergency firmware protects seeds generated from now on. A seed created on the flawed firmware stays reproducible, so affected owners have to generate a brand new wallet and move their funds to it.

    How much bitcoin was stolen in the Coldcard exploit?

    Galaxy Research counts 1,367.05 BTC, about $88.6 million, across 4,585 addresses in three waves through August 1. All of it remains unspent in attacker-controlled addresses, which researchers call unusual for a theft this size.

    Can Coldcard owners check whether their wallet is at risk?

    Not reliably. There is no test an owner can run against their own wallet that reveals whether the seed falls inside the guessable range, which is why the guidance is to move funds rather than wait and see.

    innovationgovernment & fraudcrypto & defi
    Share

    RELATED COVERAGE

    Kalshi Ends Its Trader Volume Rewards a Year Early as Wash Trading Scrutiny Grows

    Sep 30, 2026 · 3 min read

    House Oversight Expands Its Prediction Market Probe to Crypto.com, Hyperliquid, and PredictIt

    Sep 30, 2026 · 3 min read

    Goldman Sachs Opens Its $100 Billion Treasury Fund to Crypto Firms Through Lynq

    Sep 30, 2026 · 2 min read

    Don't miss the next story.

    Nonprofit data, crypto markets, policy — every Friday. Under 5 minutes.