cryptocurrency widget, price, heatmap
arrow
Burger icon
cryptocurrency widget, price, heatmap
News/Coldcard Exploit Losses May Reach $114 Million After Fourth Sweep

Coldcard Exploit Losses May Reach $114 Million After Fourth Sweep

Van Thanh Le

Van Thanh Le

PublishedAug 3 2026

UpdatedAug 3 2026

hace 5 horas5 minutes read
Robot Guardian in Bitcoin Transaction Vault

Predictable seed generation left thousands of Bitcoin addresses exposed to coordinated theft

TL;DR

  • Three tracked attack waves drained 1,367 BTC worth $88.6 million from 4,585 addresses.
  • A suspected fourth sweep raised potential losses to about 1,816 BTC, or nearly $114 million.
  • The flaw involved predictable seed generation, requiring affected users to create new seeds and move their funds.

Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity. 

Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!


A suspected fourth sweep of Bitcoin wallets generated with vulnerable Coldcard firmware may have raised total losses to about 1,816 BTC, worth nearly $114 million, across more than 5,200 addresses. The earlier three waves were tracked more firmly at 1,367 BTC worth $88.6 million from 4,585 addresses, while the latest total remained an onchain estimate because affected users had not directly confirmed every transaction.

tweet-2084099439359373416.webp

Galaxy Research head of firmwide research Alex Thorn said he issued an urgent warning while suspicious transactions were still unconfirmed. Thorn had not received direct reports from victims confirming the fourth wave, but said the transactions resembled vulnerable Coldcard unspent transaction outputs and appeared at an abnormally elevated rate.

The fourth-wave figure therefore remained a high-confidence onchain assessment rather than a final forensic count. Researchers were still removing incorrectly classified transactions, expanding the address set and monitoring funds that had already moved beyond their initial destinations.

Firmware error created predictable Bitcoin seeds

The vulnerability was traced to a March 2021 firmware build error that could send seed generation through a predictable software random-number generator instead of the hardware chip’s intended entropy source. The weakened generator drew from a smaller and more predictable range, potentially allowing an attacker to reconstruct affected private keys offline without obtaining the physical wallet.

Affected Coldcard Mk3 devices were identified as those running firmware versions 4.0.1 through 4.1.9. The wider response included emergency firmware for affected models and renewed scrutiny of how newer devices validate the entropy used to generate recovery seeds.

The defective code path may have produced guessable private keys for approximately five years. Installing updated firmware cannot strengthen a seed that was previously created with insufficient randomness, meaning affected holders must generate a completely new seed and transfer their Bitcoin to addresses derived from it.

Initial estimates of the first attack wave converged on a 41-minute sweep that began on July 30, during which 1,083 BTC were taken from 1,196 addresses. Two additional waves over the weekend later brought total observed losses to 1,367 BTC across 4,585 addresses.

orshot-1785759468067.webp

At least one Canadian holder was identified as having lost $1.6 million, showing that balances taken during the exploit included substantial individual holdings rather than only abandoned wallets or small outputs.

The reported value of the incident climbed rapidly as the suspected address set expanded. The loss estimate began near $38 million when the defect became public, moved toward $70 million when Binance founder Changpeng Zhao warned holders, and reached the firmer three-wave assessment before the latest suspected sweep emerged.

Fourth wave remained active as researchers warned users

The suspected fourth attack began early Monday and continued for hours while analysts tracked confirmed transactions and similar transactions waiting in Bitcoin’s mempool.

An initial Galaxy Research analysis identified 218 transactions between blocks 960,778 and 960,792. Those transactions moved more than 380 BTC from 462 suspected victim addresses into 210 newly created destination addresses.

The activity averaged about 13.8 sweeps per block, compared with a control rate of approximately 0.3 per block before the incident. That made the observed sweep rate roughly 45 times higher than normal.

Thorn said the addresses were “LIKELY Coldcard victims” because their outputs matched the structure associated with vulnerable wallets and appeared within the sharply elevated transaction pattern.

tweet-2084079706320646300.webp

Some stolen Bitcoin had already moved from its first destination into second-hop wallets, showing that the funds were beginning to disperse while researchers were still mapping the affected addresses.

A later analysis examined 15 consecutive blocks and removed transactions that had been incorrectly classified as affected multisignature wallets. That broader and corrected dataset estimated the fourth wave at 709 addresses holding 448.73 BTC worth approximately $28 million.

The difference between the initial fourth-wave scope and the later estimate reflected an expanding dataset followed by classification corrections. It did not indicate that two separate fourth waves had occurred.

No addresses identified during the first three waves used multisignature configurations. Researchers also removed six destination addresses with years of previous transaction history because newly created attacker-controlled addresses would not normally have an established record.

The attacker’s fourth-wave transaction structure also differed from the earlier sweeps. Each victim’s balance appeared to move into a separate unused destination rather than being consolidated immediately into shared collection wallets, making the latest cluster more difficult to trace.

Analysts filtered for Bitcoin received after the relevant Coldcard firmware boundary, strengthening the association between the affected outputs and seeds created after the defective software entered circulation.

Many suspected fourth-wave transactions had replace-by-fee enabled. Replace-by-fee allows an unconfirmed Bitcoin transaction to be replaced by a competing transaction that spends the same inputs and pays a higher network fee.

Thorn told users whose suspicious transactions remained unconfirmed that they “may be able to RBF your way out of this.” A holder who identified a pending theft quickly could attempt to move the same coins to a secure wallet while offering miners a higher fee than the attacker.

That recovery option applied only while a transaction was waiting in the mempool. A competing transaction could no longer reverse the transfer after the attacker’s transaction had been confirmed in a block.

Coinkite halted shipments and issued emergency firmware

Coinkite released emergency firmware and instructed anyone who generated a seed using affected software to create a new one and transfer the funds to a newly derived wallet.

Coinkite said Sunday, Aug. 2, that it had halted product shipments and destroyed all remaining inventory containing the flawed firmware. The company said Satscard, Opendime and Tapsigner were unaffected.

The company advised users to retain compromised devices because its legal team was coordinating with law-enforcement authorities and the hardware could become relevant to investigations, evidence preservation or claims.

Coinkite also said it had contacted hardware-wallet manufacturers, security researchers and other self-custody participants that had offered resources. The company said it was “committing to work with the broader industry going forward.”

Changpeng Zhao separately warned users about hardware-wallet risks as the estimated losses grew, highlighting that a dedicated signing device does not protect funds when its private-key generation process is defective.

Kraken chief security officer Nick Percoco called the incident a “wake-up call for the entire hardware wallet industry.”

Percoco said Coldcard Mk4, Mk5 and Q devices contained certified secure elements, but the seeds involved reportedly carried only about 72 bits of entropy. Certification validated the component itself without proving that the wallet’s firmware was using the intended randomness source.

Percoco proposed independent laboratory validation of wallet entropy sources, with testing results tied to individual firmware versions and recorded in a public registry. He compared the proposed structure with security requirements for payment terminals, where assessments cover a defined combination of hardware, software and operating configuration.

Coinkite’s hotfix changed its build process so compilation would fail unless the correct random-number generator was linked. Percoco said the safeguard took about 48 hours to implement after the company understood what the build system needed to detect.


We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!

Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.


Smaller Bitcoin holders moved funds at unusual scale

The exploit disclosure coincided with an exceptional increase in Bitcoin movements by smaller holders on July 31.

Metric Observed level Comparison
Transfers below 1 BTC 39,600 BTC, worth approximately $2.5 billion 39,900 BTC on Nov. 16, 2022, several days after FTX collapsed
Daily active addresses Nearly 1 million Approximately 645,000 on July 30; highest since December 2024
Exchange deposits below 10 BTC 7,300 BTC, worth approximately $459 million Highest level since Feb. 6

CryptoQuant Head of Research Julio Moreno wrote, “The Bitcoin plebs had not move this amount of BTC in a day since the FTX collapse.”

The increase in active addresses was concentrated among sending addresses rather than receiving addresses, indicating that existing holders were initiating movements rather than the increase being driven only by new recipients.

Moreno said users appeared to be “looking for safety,” while cautioning that the connection between the Coldcard exploit and exchange deposits had not been definitively established.

tweet-2083768184176324737.webp

Bitcoin showed little immediate market reaction despite the exchange inflows, supporting the stated possibility that holders were moving assets for custody reasons rather than preparing to sell.

The onchain activity cannot be treated as a complete victim count. The figures describe broader behavior that occurred alongside the vulnerability disclosure, and not every small transfer or exchange deposit was shown to involve an affected Coldcard wallet.

ZachXBT declined to trace the stolen funds

Blockchain investigator ZachXBT said he had no current plans to trace the incident’s $88.6 million confirmed loss total.

ZachXBT said he was focusing his time on ecosystems that supported and valued his investigative work. He argued that Bitcoin maximalists had not been significant donors or supporters of his previous investigations and said he felt less obligated to assist.

orshot-1785759803991.png

The decision shifted more responsibility toward Galaxy Research and other firms publishing address-by-address assessments of the attack waves.

The speed and precision of the thefts prompted speculation that automated or potentially AI-assisted tools were used to find vulnerable addresses and empty them within minutes. No evidence established that artificial intelligence was involved.

A party also posted a Bitcoin-laundering offer directed to the attacker on the Bitcoin blockchain, permanently recording the solicitation.

Data retention practices created a separate dispute

Coinkite used store and newsletter records, including email addresses dating to 2019, to contact customers about the vulnerability.

That outreach conflicted with previous statements from Coinkite CEO Rodolfo Novak that customer data was erased 90 days after a purchase and that customers could buy products anonymously.

Coinkite later acknowledged that purchase email addresses were retained indefinitely and that no formal deletion policy covered those records.

Novak defended the company’s broader security record by saying competing companies also suffer breaches and that Coinkite was treating the incident extremely seriously.

The combination of the firmware failure and customer-data dispute was presented as a possible reason more cautious investors could choose exchange-traded fund exposure over direct private-key management. No measured fund-flow data supported that possible shift.

Peter Todd defends self-custody after Coldcard losses

Bruce Fenton cited the incident as evidence that consumer self-custody can fail catastrophically when users rely on defective hardware or cannot independently verify the systems protecting their keys.

tweet-2084093028310905282.webp

Early Bitcoin developer Peter Todd rejected the conclusion that the Coldcard flaw made centralized custody safer. Todd compared the losses with the collapse of Canadian exchange QuadrigaCX, which caused approximately $200 million in losses.

Todd argued that QuadrigaCX’s losses were more than twice the Coldcard total discussed at that stage, showing that transferring control of private keys to a centralized third party carries a separate and potentially larger risk.

Todd acknowledged the risks of weak entropy, undiscovered technical defects and user mistakes, but said they did not remove the structural benefit of controlling private keys.

He compared protecting a 12-word recovery seed with safeguarding a birth certificate and said users should avoid placing every recovery method in one physical location.

Todd also compared self-custody education with learning to drive, noting that people accept hundreds of hours of instruction and sustained concentration to operate a vehicle despite the consequences of a serious mistake.

He said structured education lasting several weeks could reduce critical private-key management errors to almost zero.

Responding to suggestions that users separate wallet backups or divide their holdings, Todd called them “two very obvious strategies that any adult would consider.”

FAQ

What caused the Coldcard exploit?

A firmware build error used a predictable software random-number generator during seed creation.

Can installing new firmware protect an existing seed?

No. Affected users must generate a new seed and transfer their Bitcoin.

Why could some users stop pending thefts?

Replace-by-fee allowed competing transactions with higher network fees before confirmation.

Which Coinkite products were identified as unaffected?

Satscard, Opendime and Tapsigner.

This article has been refined and enhanced by ChatGPT.

cryptocurrency widget, price, heatmap
v 5.13.12
© 2017 - 2026 COIN360.com. Todos los derechos reservados.