top of page

The Coldcard Hack and What It Teaches About Security

Aug 4
10 min read

Coldcard Hacked: $116 Million in Bitcoin Drained, and the Lesson Nobody Wants to Say Out Loud


A hardware wallet is supposed to be the safest place to keep Bitcoin.

The device never connects to the internet. The private keys never leave it. You keep it in a drawer, a safe, a safety deposit box. The whole point is that no one can steal your funds without physically holding the device.

On July 30, 2026, that promise failed for thousands of people.

A firmware flaw in Coldcard wallets made by Canadian manufacturer Coinkite turned five years of assumed security into a vulnerability that an attacker could exploit without ever touching the device. Three waves of attacks between July 30 and August 3 drained 1,367 Bitcoin from 4,585 addresses. By August 3, Fortune was reporting total losses approaching $116 million.

The attacker did not need the physical device. Did not need the PIN. Did not need to trick anyone into clicking a phishing link. They reconstructed the seed phrase mathematically and swept the funds.

This is the story of what happened, what it means for everyone who uses hardware wallets, and the security principle that this incident makes impossible to ignore any longer.


What Happened: The Technical Breakdown

A single commit in March 2021 broke five years of security

To understand this exploit, you need to understand one concept: entropy.

When you set up a hardware wallet, the device generates your seed phrase, the 12 or 24 words that control everything. The security of that seed depends entirely on how random those words are. If the randomness is truly unpredictable, guessing your seed is computationally impossible. If the randomness is weak or predictable, an attacker can reconstruct your seed without ever touching your device.

On March 1, 2021, a single code change in Coldcard's firmware caused the device to silently fall back to a software-based random number generator instead of the dedicated hardware one. On Mk3 devices, the effective search space collapsed to roughly 40 bits. Coinkite confirmed that figure.

To put that in perspective: a truly secure seed has 128 bits of entropy. Guessing it is more difficult than counting every atom in the observable universe. With 40 bits, a well-equipped attacker can brute-force the space in hours, or even minutes if they can identify patterns from the deterministic fallback. The device generated keys using values as predictable as its own serial number.

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking over 1,082 BTC. Galaxy Research mapped the sweep and tied it directly to this firmware flaw. Three waves followed, each expanding the scope.


Which devices are affected

Coinkite's advisory confirms the vulnerability in Coldcard Mk2 and Mk3 devices that generated a wallet seed on firmware v4.0.0 through v5.0.3. Every wallet created on those firmware versions, covering the period from March 2021 through v5.0.3, is in the confirmed vulnerable window.

Mk4, Q, and Mk5 devices are not affected by the active exploit. Seeds generated by the user with 50 or more die rolls rather than relying on device randomness are at lower risk. Coinkite's other products including TAPSIGNER, OPENDIME, and SATSCARD were not affected.

If you added a strong BIP-39 passphrase (sometimes called the 25th word) that was never typed into any internet-connected device, Coinkite says your risk from this specific vulnerability is significantly reduced. The passphrase adds entropy that the attacker cannot reconstruct from the device's weak randomness alone.


The attack pattern

What stands out in Galaxy Research's analysis is the attacker's operational discipline. Across all three waves of attacks, the stolen coins have not been moved or spent. They sit in the drained addresses, accumulated but untouched, suggesting either a sophisticated actor waiting for the right moment to move funds or multiple independent actors who have not yet decided how to proceed.

Galaxy Research believes each wave is the work of a single operator but cannot determine whether the same attacker is behind all three, as the blockchain does not reveal whether separate sweeps are coordinated.


What to Do If You Have a Coldcard

Check first. Move second. Do not rush.

Coinkite issued an important warning alongside the patch: "Rushing a wallet migration can create a more immediate risk than the issue you are trying to address."

This is counterintuitive advice when you hear your wallet might be compromised. But it is correct. Panicked migrations produce mistakes. Follow these steps in order.


Step 1: Identify your device and firmware history. Check which Coldcard model you have and when you created your seed. The vulnerable window is Mk2 and Mk3 devices where the seed was generated on firmware v4.0.0 through v5.0.3, covering any seed created between March 2021 and your last firmware update before v5.0.3.


Step 2: Check if you used a BIP-39 passphrase. If you added a strong passphrase at setup and it was never typed into any internet-connected device, your risk from this specific exploit is significantly lower.


Step 3: If you are in the vulnerable window, create a new wallet on a different device. Do not just update firmware. Updating firmware patches the vulnerability going forward but does not repair a seed that was already generated with weak randomness. The compromise happened at seed creation. The fix is a new seed on a non-affected device.


Step 4: Transfer funds carefully. Move to the new wallet in a controlled way. Verify the new wallet functions correctly before transferring everything. Test with a small amount first.


Step 5: Do not announce your timeline publicly. Saying "I'm moving my Bitcoin this weekend" is an invitation for social engineering attacks targeting you in the window between old wallet and new.


The Broader Lesson: Self-Custody Moves the Risk, It Does Not Remove It

The most important thing to understand about hardware wallets

"Coldcard shows that self-custody moves the risk, it does not remove it." That line came from Ari Redbord, TRM's global head of policy, and it is the most honest framing of what this incident means.

Self-custody removes counterparty risk: your funds cannot be frozen by an exchange, lost in a platform bankruptcy, or blocked by a compliance department. Those are real and documented risks that self-custody genuinely protects against.

But self-custody introduces a different category of risk: firmware integrity, supply chain security, and the quality of the entropy your device used when it generated your keys. This incident demonstrates that self-custody security has two independent requirements: controlling your keys, and ensuring those keys were generated with genuine randomness. Hardware wallet marketing has historically been much stronger on the first than the second.

Both categories of risk are real. The Coldcard incident does not prove self-custody is wrong. It proves that self-custody done carelessly is as dangerous as any other approach.

The attack also fits a broader 2026 pattern. According to blockchain security firm Blockaid, most crypto losses in the first half of 2026 came not from smart contract hacks but from compromised keys and operational security failures. Over the past six months, attackers launched 207 separate incidents, the highest number ever recorded in any half-year period by TRM Labs. Total losses reached about $972 million, less than half of the $2.3 billion stolen in the first half of 2025. Fewer dollars, more incidents. The attacks are not getting less frequent. They are getting more targeted and more sophisticated.


Diversification Is Not Just for Portfolios: It Is a Security Principle

Why keeping everything in one wallet or one type of wallet is a structural mistake

CZ, Binance's founder, responded to the Coldcard incident by publicly calling for wallet diversification. His message was simple: no single solution is immune to flaws, including long-established and highly regarded hardware wallets.

The principle is straightforward and applies to security exactly as it applies to investment portfolios.

Multiple wallets, multiple manufacturers. If you hold significant amounts across two hardware wallets from different manufacturers using different firmware stacks, a vulnerability in one does not compromise everything. Coldcard is Coinkite. Trezor is SatoshiLabs. Ledger is a French company with its own firmware. These are independent codebases. A bug in one is not a bug in the others.

Separate wallets for separate purposes. Keep a hot wallet with a small amount for active DeFi use and transactions. Keep long-term holdings in cold storage on hardware wallets. If the cold storage holds significant value, consider using hardware wallets from two different manufacturers stored in separate physical locations.

Multisignature setups for high-value holdings. A multisig arrangement requires signatures from multiple independent keys before a transaction can be executed. A vulnerability in one device does not drain the wallet because the attacker would also need to compromise the other signing keys simultaneously. This is the standard used by institutional holders for exactly this reason.

Die-roll entropy for new seeds. The Coldcard vulnerability specifically targeted device-generated seeds. For new wallet setups, generating your seed with physical dice removes the dependency on device firmware randomness entirely. The seed exists before the device ever touches it.

The full guide to hardware wallets, cold storage options, and security practices is in the CryptoDroply Wallet section →, with options vetted for security track record across all major manufacturers.


Stablecoins: The Same Diversification Logic, Often Ignored

Why concentrating stablecoin holdings is the same structural mistake

The Coldcard incident is about Bitcoin security, but the principle it illustrates applies equally to stablecoin holdings. This is a point that rarely gets addressed directly, and the Coldcard week happened to coincide with two other stablecoin incidents that make the argument even more concrete.

While Coldcard was being exploited, blockchain network WEMIX announced that an attacker had compromised ownership of its WEMIX$ stablecoin. Singapore stablecoin payments company Triple-A suffered a separate breach affecting company assets. These were separate incidents from the Coldcard attack, occurring in the same week.

The stablecoin landscape has distinct risk categories that are rarely explained clearly:

USDT is issued by Tether Limited, a private company in the British Virgin Islands. It is the most liquid stablecoin globally and the most widely used. It is not MiCA compliant, meaning EU-regulated exchanges cannot offer it to retail clients. Its reserves are attested quarterly, not verified in real time. The risk is issuer risk: if Tether faces a regulatory action, a freeze order, or a solvency event, USDT holders on custodial platforms are exposed.

USDC is issued by Circle, a US company with significant regulatory compliance investments and MiCA authorizations in Europe. More transparent reserves, more regulatory relationships, different counterparty risk from USDT. A different issuer, a different jurisdiction, a different regulatory posture.

DAI and USDS (formerly DAI, now the Sky Protocol stablecoin) are decentralized stablecoins backed by crypto collateral through smart contracts. Issuer risk is replaced by smart contract risk and collateral risk. A protocol exploit or a collateral collapse affects them differently from how a regulatory action affects USDT.

Newer stablecoins like USDG on Robinhood Chain are less battle-tested but part of an increasingly competitive landscape.

No single stablecoin is risk-free. Concentrating all stablecoin holdings in one issuer creates a single point of failure. Distributing across two or three stablecoins with different risk profiles means that a problem with any one of them does not eliminate your entire dollar-denominated position.

This is not about expecting USDT to collapse or USDC to freeze. It is about understanding that every instrument has a specific failure mode, and that diversification is what limits the damage when that failure mode is triggered.


The Full Security Checklist

For hardware wallet holders:

Check your Coldcard model and the firmware version it was running when you created your seed. If you have a Mk2 or Mk3 and created your seed after March 2021 without a strong BIP-39 passphrase, plan a migration to a new wallet on a different device. Do not rush. Test the new wallet thoroughly before moving everything.

For any hardware wallet: use wallets from at least two different manufacturers if the value you are protecting warrants it. Use a strong BIP-39 passphrase and store it separately from the seed phrase itself. Consider multisig for significant holdings.

For all self-custody users:

Never keep more than you actively need in a single wallet. Review token approvals on hot wallets regularly and revoke unused ones. Keep firmware updated on all devices, and verify that updates come from official sources only.

For stablecoin holders:

Do not keep all stablecoin holdings in a single issuer. Distribute across two or three stablecoins with different risk profiles and different custodial structures. Understand what you are holding: USDT carries Tether issuer risk, USDC carries Circle regulatory risk, decentralized stablecoins carry smart contract and collateral risk. Different risks, all manageable through diversification.


FAQ

Am I at risk if I have a Coldcard?

You are at confirmed risk if you have a Mk2 or Mk3 device and generated your seed on firmware v4.0.0 through v5.0.3 (any seed created between March 2021 and your last update). Mk4, Q, and Mk5 devices are not affected by the active exploit. Seeds generated with 50+ die rolls rather than device randomness are also at lower risk.

Will updating my Coldcard firmware fix the problem?

No. Updating firmware patches the vulnerability going forward but does not repair a seed that was already generated with weak randomness. The compromise happened at seed generation. The fix is creating a new seed on a non-affected device and migrating your funds to the new wallet.

Is self-custody still the right approach?

Yes, but done correctly. Self-custody removes counterparty risk: exchanges cannot freeze your funds, platforms cannot go bankrupt with your assets. Those risks are real. But self-custody introduces firmware and key generation risk. The response is not to abandon self-custody. It is to distribute across multiple devices and manufacturers so no single vulnerability wipes out everything.

How do I diversify stablecoins properly?

Hold stablecoins across two or three different issuers with different risk profiles. USDT (Tether issuer risk), USDC (Circle regulatory risk), and a decentralized option like USDS (smart contract risk) cover different failure modes. No single event can simultaneously affect all three in the same way.

What is a BIP-39 passphrase and does it protect against this exploit?

A BIP-39 passphrase, sometimes called the 25th word, is an additional word you add to your seed phrase at setup. It creates a completely separate wallet derived from the same base seed. Coinkite confirmed that users who set a strong passphrase that was never typed into any internet-connected device are at minimal risk from this specific exploit, because the passphrase adds entropy the attacker cannot reconstruct from device randomness alone.


The Coldcard hack is not evidence that hardware wallets do not work. It is evidence that no security solution is immune to the quality of its own implementation, and that the promise of cold storage was always contingent on the firmware generating your keys being trustworthy.

Self-custody moves the risk. It does not remove it.

That is the entire lesson, and it applies to everything: hardware wallets, stablecoin holdings, exchange accounts, DeFi protocol interactions. Every instrument has a failure mode. The job of a serious crypto user is not to find the one thing that has no risk. It is to understand the risk profile of each instrument and distribute so that no single failure can take everything.

Security is not a product you buy once. It is a set of practices you maintain continuously. The Coldcard incident just made that a $116 million lesson for the people who learned it the hard way.

You can learn it differently.



PRO members get in-depth security guides, hardware wallet setup checklists, and weekly updates on incidents across the ecosystem so you find out before it costs you.


 
 
bottom of page