Coldcard’s $130M hack wasn’t a cold storage failure. Read the bug.
Coldcard wallets lost about $130M in bitcoin. The devices stayed offline the whole time. The flaw was a disabled random generator that made seeds guessable.
The Editors · 8 min read ·
Coldcard, one of the most trusted names in bitcoin self-custody, lost roughly $130 million in customer funds over five days at the end of July 2026, according to Galaxy Research and Elliptic. The wallets that got drained were doing everything the manuals told them to do. They were offline. They were air-gapped. Some had sat untouched for years.
The theft did not come from a stolen device or a phishing link. It came from the moment each wallet was created. A firmware bug quietly switched off the chip that produces true randomness, and a fallback kicked in that built the secret key from the device serial number and its internal clock. Neither of those is secret. So the keys were guessable from the day they were made.
If you hold bitcoin on a Coldcard, the short version: check which firmware generated your seed, and if it is on the affected list, move your coins to a new wallet now. The rest of this piece explains what broke, how attackers cashed in, and why "keep it in cold storage" was never the safeguard people thought it was.
The bug: one flag, one missing check
A hardware wallet has one job that matters more than any other. It has to generate a seed phrase, the 12 or 24 words that are your keys, from randomness so good that no one, anywhere, can reproduce it. Coldcard devices have a dedicated STM32 hardware chip for exactly this. Real physical randomness, not math dressed up to look random.
The bug turned that chip off. A build setting told the device to skip the hardware source, and the code that was supposed to catch this tested only whether the setting existed, not whether it was switched on. With no working hardware entropy, key generation fell back to MicroPython's deterministic Yasmarang generator, seeded from the device serial number and its clock registers. Both are factory metadata. An attacker who can pin down those values can rebuild the same "random" seed on their own machine.
The flaw traces to a commit dated March 1, 2021, shipped in firmware 4.0.0. Coldcard's source code is public. The bug sat there, readable by anyone, for five years before it was exploited.
What 128 bits buys you, and what 40 buys an attacker
The number that matters here is entropy, measured in bits. A standard 12-word BIP-39 seed carries 128 bits of it. That is the whole game: 128 bits is a space so large that guessing your specific key by brute force is not feasible with any amount of computing power on Earth.
The affected seeds did not have 128 bits. On Mk3 devices, real entropy collapsed to roughly 40 bits; on Mk4, Mk5 and Q models, to about 72.
Forty bits is roughly a trillion possibilities. That sounds like a lot until you remember a modern machine can churn through it in a manageable window, and the attacker was not guessing one wallet at a time. Seventy-two bits is harder, but for a funded operator running the search across thousands of candidate wallets at once, it moved from "impossible" to "worth doing."
41 minutes, 1,196 wallets
The first sweep came on July 31. About 594 BTC, roughly $38 million, moved in 25 minutes, from 01:31 to 01:56 UTC, across around 500 wallets. Then it grew. One wave took 1,082.65 BTC, about $70.2 million, from 1,196 addresses in 41 minutes. Investigators later tied 1,367.05 BTC across 4,585 addresses, near $88.6 million to the exploit, with the widest estimate reaching about 2,055 BTC across more than 7,700 addresses, roughly $130 million.
This was not one crew. Galaxy Research counted at least a dozen different hackers, and more than one group. Once the seeds were reproducible, Block's security researchers found attackers could brute-force and generate the victims' seed phrases at scale, then drain in bulk. The drained wallets shared a profile: single-signature setups, balances over 0.15 BTC, dormant for a long stretch, and creation dates spanning 2021 to 2026.
Which devices, the part still moving
The scope is not fully settled, and honesty here matters more than a clean number. Reporting agrees that Coldcard Mk3 units generating seeds on firmware 4.0.1 or later are affected. Beyond that, accounts diverge. Some early technical write-ups said Mk4, Q and Mk5 models appeared unaffected. Later analysis put those models at about 72 bits of entropy and flagged anything before firmware 5.6.0, with Q before 1.5.0Q.
The total loss is moving too, from a confirmed ~$89 million to an estimated ~$130 million as more addresses got linked. The practical read for a holder: treat the wider figure as the working number, and treat your own device as suspect until you have checked the firmware that made your seed.
Cold storage was never the safeguard
Every headline calling this proof that "even the safest wallet can be hacked" is aiming at the wrong target. The device stayed offline the entire time. Air-gapping worked. It protected the key after the key existed, which is all air-gapping ever does.
The security of a seed phrase rests on one assumption underneath everything else: that the words came from randomness no one can reproduce. Coldcard broke that assumption at the source, in the one moment self-custody gives you no way to audit. You can verify your balance. You can verify your firmware version. You cannot look at your seed and tell whether it was born from 128 bits of real entropy or 40 bits of a serial number and a clock. "Not your keys, not your coins" tells you to hold the key. It says nothing about whether the key was any good in the first place. As one security officer put it, the lesson is concentration: "a single secret, created on a single device, in a single unrepeatable moment."
What actually protects a self-custody stack
This is not a reason to hand your coins back to an exchange. It is a reason to stop treating one device as the whole of your security. A few concrete moves, in order of leverage:
- Check the firmware that generated your seed, not the version running now. The bug is in when the key was made. A patched device holding an old, weak seed is still exposed.
- If your seed is affected, generate a fresh one on patched firmware and move the funds. Coldcard shipped emergency firmware on July 31. Do not wait for proof you were targeted.
- Add your own entropy. Many wallets let you roll physical dice into the seed. That removes sole reliance on any one chip's randomness, because even a broken RNG cannot cancel out dice you rolled yourself.
- Use multisig for meaningful balances. Spreading keys across devices and vendors means one broken generator does not expose the whole balance. The wallets that got drained were single-signature.
Self-custody trades counterparty risk for operational risk. Holding your own keys removes the exchange that can freeze or lose your funds, and hands you a different job: making sure the whole chain from key generation to storage actually holds. This is what that job looks like when one link fails, and it sits inside a brutal year. TRM Labs counted more than 200 crypto hacks in the first half of 2026, over $950 million in losses. If you are weighing self-custody against the alternatives, our options for holding money in 2026, ranked by risk, puts this kind of operational risk next to the others.
To its credit, Coldcard did not hide. Founder Rodolfo Novak apologized publicly, said the company takes full accountability, and offered help with police reports, insurance claims and blockchain investigations. As of August 3, reimbursement was not on the list.
The open question now points past Coldcard. How many other vendors ship a hardware RNG that a single build flag can silently disable, with no check that it is actually running? Entropy is the one part of self-custody nobody can see by looking at their balance. Bitcoin traded near $64,000 while this played out, moving with its longer-term trend rather than the news, so the dollar total will shift with the price. The lesson holds at any price.
Sources
- Hackers steal over $130 million by exploiting bug in offline hardware wallets, TechCrunch, August 4, 2026
- Coldcard hardware wallet flaw linked to $70 million bitcoin theft in 41 minutes, The Hacker News, August 2026
- Coldcard crisis hits $130 million, CryptoSlate, August 2026
- 594 BTC gone in 25 minutes: the Coldcard flaw that made seed phrases guessable, CryptoTicker, August 2026
- Hackers target bitcoin's safest hiding place in ongoing attack, Bloomberg, August 3, 2026
- Crypto market today, Aug. 4: Bitcoin steadies near $64,000, The Motley Fool, August 4, 2026
This is not financial advice.