The Coldcard firmware exploit is now one of the largest hardware wallet security failures in crypto history — and a turning point for how the industry thinks about crypto wallet security, bitcoin self custody, and the case for institutional crypto custody.
On July 30, 2026, roughly 594 bitcoin — approximately $38 million — was stolen from around 500 dormant wallets in under 30 minutes. This didn’t need a phishing email, or even physical access to a device. No user interaction was required at all. The attacker reconstructed private keys remotely by exploiting a Coldcard firmware bug that had been present since March 2021.
Subsequent waves of attacks have pushed confirmed losses to 1,596 BTC from more than 7,300 wallets, with suspected losses reaching approximately 2,055 BTC, roughly $130 million, across more than 7,700 addresses, according to Galaxy Research. As of early August 2026, the attacks are ongoing and the final figure is likely to rise further.
The root cause was a flaw in how certain Coldcard models generated wallet seeds. Affected firmware versions on the Mk3, Mk4, Mk5, and Q devices had created seed phrases using a software-based pseudo-random number generator instead of the hardware's true random number generator, reducing their randomness to a level that made them computationally brute-forceable. Every drained wallet was single-signature, many had been dormant for years, and the coins they held spanned the full period the bug was active.
To be clear: this is not a flaw in Bitcoin. The Bitcoin network's cryptographic foundations remain secure and are operating as intended. This was a firmware implementation error in a specific hardware wallet product.





