One silent software bug turned Bitcoin’s “safest” wallet into a jackpot, letting thieves script away almost $89 million while no one touched a single device.
Story Snapshot
- Attackers drained about 1,367 Bitcoin from 4,585 addresses across three rapid waves.
- A random-number bug in Coldcard firmware made some seed phrases predictable and brute-forceable.
- Galaxy Research and other teams mapped a 41‑minute sweep of 1,196 wallets for roughly $70 million.
- Coinkite has admitted the flaw, pushed urgent patches, and warned users their “cold storage” may not be cold at all.
How nearly $89 million vanished from “offline” Bitcoin vaults
Security researchers say the story began in the dead of night on July 30, 2026, when a cluster of Bitcoin addresses suddenly emptied in tight formation. Galaxy Research later showed that in just 41 minutes, 1,196 addresses were swept for 1,082.65 Bitcoin, worth about $70 million at the time.
No one clicked a fake link. No malware popped up. Funds simply moved out, block by block, as if some invisible master key had been handed to the thief.
That first wave was only the opening act. Follow‑up analysis by Galaxy and others tracked two more rounds of coordinated theft, smaller per victim but broad in reach. By early August, the tally had climbed to about 1,367 Bitcoin stolen from 4,585 addresses, or nearly $89 million in value.
The pattern was eerily consistent: dormant wallets, single‑signature setups, balances above a modest floor, all drained without any sign the owners had ever gone online at the same time.
The flaw inside Coldcard that broke the idea of “air‑gapped” safety
Engineers at Block’s Bitcoin team and outside researchers soon converged on one culprit: a firmware bug in Coldcard hardware wallets, made by Canadian company Coinkite.
Coldcard devices are supposed to use a hardware random number generator to create the seed phrase that protects your Bitcoin. That seed is the root secret; if it is truly random and never shared, no one can guess it in any human timescale.
BREAKING: 🚨 A suspected fourth wave of attacks linked to the Coldcard wallet vulnerability may have pushed total losses to 1,816 BTC, worth roughly $114 million.
More than 5,200 addresses may be affected since July 30. pic.twitter.com/h6cs8mIjUV
— Crypto Pay (@cryptopaydotcom) August 3, 2026
In certain versions released after March 2021, that promise quietly failed. Due to a configuration mistake in the code, affected devices sometimes skipped the hardware random source and fell back to a deterministic software generator, meaning it followed a predictable pattern tied to non‑secret data on the chip.
In plain English, the “random” seed was not really random. It was more like a very complicated but repeatable lock combination that an attacker could reconstruct.
How attackers turned a firmware mistake into a Bitcoin harvest
Once researchers realized the seed phrases came from a weak, repeatable process, the attack chain looked brutally simple in concept. A determined thief could simulate the flawed Coldcard software offline, feed it the same starting values, and map out huge numbers of possible seed phrases and matching private keys.
They could then scan the public blockchain for any addresses funded from those keys and build a hit list of real wallets at risk, all without touching the devices or tipping off owners.
When ready, the attacker could script a mass sweep: sign transactions from those keys and push them in rapid bursts to drain every targeted address. That is exactly what the on‑chain data shows.
The first wave focused on high‑value addresses, averaging close to a full Bitcoin each, while later waves spread across thousands of smaller wallets.
Coldcard’s response, responsibility, and what conservative common sense says
Coinkite has since issued a security advisory, shipped patched firmware, and urged users to update and move funds off any wallet whose seed was generated on the affected versions.
The company’s leaders publicly accepted responsibility for the bug, which they trace to Mk3 firmware starting around version 4.0.1 and later extending to other models before fixes rolled out.
Coldcard Wallet Hack Drains Over 1,367 $BTC Worth ~$86 Million
Hackers have exploited a software vulnerability in Coldcard, one of the most trusted Bitcoin hardware wallets, stealing approximately 1,367 $BTC (worth around $86 million) from more than 4,500 wallets, according to… https://t.co/tzzYWcTyu4
— GUL (@gulVasikova) August 3, 2026
This episode also undercuts a popular claim in Bitcoin circles that “self‑custody on a hardware wallet is always safer than trusting anyone else.” That is only true if the hardware and software are built and tested with the same discipline we expect for critical infrastructure.
Many investors treated Coldcard as the gold standard, yet a single misconfigured flag turned their vaults into low‑hanging fruit for a patient, well‑resourced attacker.
What everyday Bitcoin holders should learn from the Coldcard exploit
The obvious lesson is practical: if your Coldcard seed came from the vulnerable firmware range, you should assume it can be guessed over time and rotate funds to a fresh, truly random wallet after updating. The deeper lesson is about trust and verification.
Even in a system built to reduce dependence on big institutions, code quality and independent security review still matter. Blind faith in a brand or a “maxi” influencer is not a risk plan.
For readers who do not live and breathe cryptography, this story shows why real‑world security is never just marketing talk. A bug that looked like a small setting error inside a niche device led to one of the largest hardware wallet failures in Bitcoin history.
The blockchain kept perfect records of every coin drained, but it could not protect anyone from a bad random number. In the end, math did what math does; it just worked for the attackers this time, not the savers.
Sources:
foxbusiness.com, thehackernews.com, coindesk.com, crypto.news, techspot.com, cryptopolitan.com, youtube.com, kucoin.com












