Coldcard Hack Losses Top $130 Million as Security Fallout Widens

Seed-generation flaw triggers continuing thefts, legal preservation steps and broader Bitcoin security review
TL;DR
- Coldcard wallets were exposed by a seed-generation flaw dating to a firmware change years before attackers began draining funds.
- Confirmed and suspected loss estimates differ because investigators are using different victim-verification and onchain-tracking methods.
- The incident has triggered customer-record preservation, a broad Bitcoin software audit and renewed scrutiny of self-custody practices.
Trade smarter on Jupiter, Solana’s leading DEX built for fast execution and deep liquidity.
Swap tokens at competitive rates, route across multiple liquidity sources automatically, and access perpetuals, DCA, and advanced trading tools — all in one place!
Coldcard's hardware-wallet security failure has grown into a theft campaign exceeding $130 million, after a seed-generation flaw dating to March 2021 weakened private keys on affected devices and allowed attackers to reconstruct vulnerable wallets without physically possessing them. The incident has since expanded beyond the original thefts, prompting Coldcard to preserve customer records for potential legal proceedings, security researchers to audit hundreds of Bitcoin projects and users to reassess how wallet randomness is generated.
The underlying flaw routed wallet seed generation through a predictable software fallback instead of Coldcard's dedicated hardware random-number generator. On older affected devices, effective key strength could fall from the intended 128 bits to as little as 40 bits, reducing the range attackers needed to search through brute-force computation. The failure meant a wallet could remain offline and physically secure while still being vulnerable if its original seed had been generated with insufficient entropy.
Updating firmware could prevent creation of new weak seeds but could not repair recovery phrases that had already been generated under the defective process. Coinkite urged affected users to migrate funds to freshly generated seeds using updated firmware. Wallets created with Coldcard's dice-roll entropy option, which allows users to supply their own physical randomness during setup, were described as unaffected.
Coinkite also destroyed remaining batches of vulnerable devices and advised users to generate new seed phrases. One estimate placed the number of potentially affected addresses at around 7,300 and said losses could approach 2,000 BTC when suspected cases were included.
Confirmed and Suspected Loss Totals Diverge
Investigators have published different totals depending on how strictly they classify an address or theft wave as confirmed. Galaxy Research counted approximately 1,596 BTC stolen across three confirmed attack waves and said a suspected fourth wave could increase the total to roughly 2,055 BTC. Galaxy did not include the additional funds in its confirmed tally because it had not received sufficient reports from affected wallet owners.
Galaxy's head of firmwide research, Alex Thorn, said blockchain evidence indicated that the suspected fourth wave was “substantially comprised of” a single attacker.
Another tracking methodology treated the suspected activity more broadly and associated the higher BTC total with more than 5,200 drained addresses. The two approaches therefore reflect different confirmation thresholds rather than interchangeable estimates.
The first major confirmed sweep took place July 30, when attackers removed 1,082.65 BTC from 1,196 addresses in 41 minutes. Galaxy later said roughly 90% of the stolen Bitcoin had remained unmoved after arriving in attacker-controlled wallets.
That dormancy subsequently broke when an attacker believed to control a large share of the stolen funds transferred 30.185 BTC, worth approximately $1.94 million, into a newly created wallet. The movement represented about 1.5% of the suspected stolen balance and was described by onchain observers as the first activity since the initial theft.
An earlier estimate had placed losses above $116 million involving more than 1,800 BTC. Confirmed attacker and victim addresses were reportedly shared with U.S. federal law-enforcement agencies, cryptocurrency exchanges and cyber-investigation firms, potentially allowing regulated platforms to flag the assets if attackers attempted to deposit them.
Canadian victims were separately identified as accounting for roughly one-quarter of the stolen funds.
Coinkite CEO Rodolfo Novak said he believed AI-assisted code review may explain why attackers found a flaw that had remained undetected by company auditors and the wider security community for about five years. The possibility that similar weaknesses could exist elsewhere led researchers to broaden their review beyond Coldcard itself.
Bitcoin Red Team Finds Thousands of Security Issues
The Coldcard incident prompted the Bitcoin Red Team, a volunteer security initiative led by BTC developer Calle alongside Rob Hamilton, CEO of self-custody insurer Anchorwatch, to conduct an emergency review of open-source Bitcoin software.
Sixteen researchers examined 390 repositories over 27.5 hours using a combination of AI-assisted analysis and manual review. They filed 4,962 security findings, including 85 classified as critical and 635 rated high severity, equivalent to an average of 2.31 high- or critical-severity findings per researcher per hour.
Opensats contributed close to $40,000 to support the security sprint. Calle described the state of ecosystem security as “extremely bad.”
The headline number did not represent thousands of independently proven exploitable vulnerabilities. Only about one in five findings had been independently reproduced at the time, leaving researchers and developers to determine which findings were genuine, reproducible and practically exploitable.
Privacy and coinjoin tools accounted for 24% of critical findings despite representing a smaller share of the reviewed projects. Cryptographic libraries produced the largest raw number of findings at 1,101, while about 10% of those were rated high severity.
Most reviewed projects had few or no critical findings. The highest-risk issues appeared concentrated among tools involved in private-key generation, transaction signing and privacy-preserving transactions, placing attention on software that performs functions similar to those implicated in the Coldcard failure.
We’ve launched the all-new COIN360 Perp DEX, built for traders who move fast!
Trade 130+ assets with up to 100× leverage, enjoy instant order placement and low-slippage swaps, and earn USDC passive yield while climbing the leaderboard. Your trades deserve more than speed — they deserve mastery.
Coldcard Pauses Routine Customer-Data Deletion
Coldcard temporarily suspended its normal automatic customer-record deletion process because of legal obligations arising from the security incident. The company said information potentially relevant to ongoing or anticipated legal proceedings needed to be preserved.
Coldcard's normal privacy process automatically blanks most customer records after 120 days, while retaining email addresses and countries of residence. Customers had also historically been able to request accelerated deletion after their orders were delivered.
Records that would normally be removed will instead be retained until the legal preservation requirement ends. Coldcard said the data would remain securely stored, access would be limited to authorized personnel and retained information would be used only to comply with legal obligations.
Customers can still contact Coldcard support and request application of the company's existing retention policy. Coldcard said its automated deletion process would resume after the legal preservation requirement ends.
The preservation decision emerged alongside separate scrutiny of Novak's historical public communications. Novak, also known as NVK, was documented deleting selected older posts from X while critics alleged that historical material had also disappeared from Coinkite-controlled webpages.
Bitcoin developer Peter Todd documented the disappearance of a November 2024 Novak post discussing a knockoff Blockclock and wrote on August 5, “Deleted recently enough it seems it was still in my phone's cache.”
Coinkite critic Greg Tonoski alleged that an entry labeled “Unnamed v.4.0.0 security issue” had been removed from a historical-disclosures page. Matthew Kratter amplified the allegation by asking whether Novak and Coinkite were deleting evidence. Coldcard responded to Tonoski, while the underlying webpage had not been archived by the Wayback Machine, leaving the allegation disputed.
Novak had not removed his entire timeline. His pinned apology over the Coldcard failure remained online, saying, “I'm sorry and I'm devastated.”
Hodlonaut separately circulated a screenshot of an earlier Novak post saying there was no need to panic. No live version remained, but Novak acknowledged that the deleted post contained “wrong” information that he intended to correct.
Zach Herbert of Foundation, identified as a direct Coinkite competitor, questioned the pattern of deletions and wrote, “What's strange is the posts that arent deleted.” Herbert added, “I originally assumed that Coinkite was under some kind of litigation hold,” followed by, “but if that was so then NVK wouldn't be deleting tweets.”
Herbert later wrote, “NVK is currently deleting old posts from 2020 to try to clean up the history,” and added, “Screenshot them while you can. They will all be gone soon.”
A Coldcard post from October 2021 remained available and stated, “Coldcard makes retirement attacks impossible.” Asked to define such an attack, Coldcard replied, “It's when the project makers could have a ‘bug’ in the entropy generation for later retrieval.”
Erin Malone had also said on August 1 that Novak was removing earlier posts, including one referring to her as a “Lightning influencer” after she challenged his claim that “Lightning barely works.”
South Korean Users Relied More on Independent Entropy
The South Korean Bitcoin community appeared to suffer almost no direct losses despite Coldcard devices being popular among experienced users. Bitcoin analyst Koji Higashi attributed the difference to a long-standing local practice of generating seed entropy independently rather than relying entirely on a hardware wallet's internal random-number generator.
Local Bitcoin educators had encouraged users to create randomness by rolling dice or flipping coins and then generate BIP39 mnemonic phrases offline. One method uses 128 coin flips to create a 12-word seed phrase or 256 flips for a 24-word phrase.
Users could then compare the generated words with a printed BIP39 word list and use an offline tool such as SeedSigner only to verify the checksum. The approach prevents a hardware wallet from becoming the sole source of randomness protecting a recovery phrase.
Higashi said larger losses in English-speaking self-custody communities may partly reflect the way recommendations circulate among influential Bitcoin personalities, including creators with sponsorships or relationships with hardware-wallet manufacturers.
He also pointed to an echo-chamber effect in technically experienced communities where widespread acceptance of a product can discourage users from questioning its security assumptions. Higashi said prominent Korean educators often had no commercial relationship with Coinkite and routinely advised users not to rely entirely on wallet firmware for seed generation.
The security practice reflects the Bitcoin principle “verify, don't trust,” extending that approach beyond software and hardware to the people recommending them.
One affected user said the vulnerable device had never connected to the internet and had remained inside a bank safety-deposit box. The seed-generation flaw meant those precautions could not protect a private key whose original randomness was already compromised.
Long-Term Bitcoin Supply Falls as Custody Debate Grows
Glassnode data showed approximately 210,000 BTC leaving the long-term-holder cohort over the week ending around August 7, the largest decline since December 2024. Long-term-holder supply fell from just under 15 million BTC to about 14.7 million BTC, while another reading placed the latest figure at 14.7729 million BTC.
Glassnode's model works at the entity level and uses coin age around a 155-day threshold to distinguish shorter- and longer-term ownership behavior rather than automatically classifying every wallet inactive for exactly that period.
Historically, large declines in long-term-holder supply had appeared around market-strength periods including March 2021, March 2024 and the later 2024 peak. This time, Bitcoin was cited around $64,000, about 50% below its October all-time high.
One interpretation linked the movement to users changing how their Bitcoin was stored after the Coldcard incident, including transfers into newly generated wallets or regulated custody services. Glassnode's metric itself does not identify where the coins went and cannot establish whether they were sold or moved among personal wallets, custodians or investment structures.
U.S. spot Bitcoin products also recorded four consecutive trading sessions of net inflows after the Coldcard incident became public, adding another data point to the custody discussion without establishing that Coldcard users were responsible for those purchases.
The custody alternatives carry different protections and risks. Eligible assets missing after failure of a SIPC-member brokerage can be protected up to $500,000 per customer, including as much as $250,000 for cash. SIPC protection does not compensate investors for losses caused by Bitcoin falling in value.
BlackRock's IBIT uses institutional Bitcoin custodians including Coinbase Custody. BlackRock states that the trust itself is not FDIC- or SIPC-insured and that neither the trust nor its sponsor insures its underlying Bitcoin.
Coinbase maintains commercial crime insurance covering certain events including theft, hacks and fraudulent transfers, but that policy is shared across Coinbase customers and may not be sufficient to cover every possible loss.
U.S. spot Bitcoin products are generally structured as exchange-traded commodity trusts rather than investment companies registered under the Investment Company Act of 1940, meaning they do not receive all statutory protections available to conventional registered ETFs and mutual funds.
A separate custody comparison cited BitGo CEO Mike Belshe's 100-BTC security wager and BitGo's use of multi-party computation, which distributes signing authority across multiple keys rather than depending on one device and one seed-generation point.
Whether the Coldcard incident ultimately causes institutional or high-net-worth users to move materially away from hardware self-custody toward MPC-based custodians remains an open question identified by the supplied reporting.
This article has been refined and enhanced by ChatGPT.