BTC $63,358.21 -0.00%
ETH $1,855.83 -1.16%
BNB $588.90 +0.56%
XRP $1.07 -0.75%
SOL $73.44 +0.10%
TRX $0.3289 +1.01%
DOGE $0.0701 -0.60%
ADA $0.1933 +2.46%
BCH $213.07 +0.37%
LINK $8.16 -2.42%
HYPE $53.78 +2.45%
AAVE $92.30 +0.59%
SUI $0.6906 +0.53%
XLM $0.1708 -1.70%
ZEC $481.64 -0.34%
BTC $63,358.21 -0.00%
ETH $1,855.83 -1.16%
BNB $588.90 +0.56%
XRP $1.07 -0.75%
SOL $73.44 +0.10%
TRX $0.3289 +1.01%
DOGE $0.0701 -0.60%
ADA $0.1933 +2.46%
BCH $213.07 +0.37%
LINK $8.16 -2.42%
HYPE $53.78 +2.45%
AAVE $92.30 +0.59%
SUI $0.6906 +0.53%
XLM $0.1708 -1.70%
ZEC $481.64 -0.34%

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

Core Viewpoint
Summary: The issue of fund security seems to never have a standard solution.
Zhou
2026-08-03 21:58:54
The issue of fund security seems to never have a standard solution.

Author: Zhou, ChainCatcher

At the end of July, the Bitcoin community was disrupted by a cold wallet security incident.

The Coldcard hardware wallet from Coinkite suffered a large-scale theft due to a firmware vulnerability that had existed for five years.

Attackers did not need to access the device, did not need phishing links, and did not need users to install any malware to remotely transfer funds. Many of the stolen addresses had been dormant for years, and the holders had never connected the devices to the internet.

According to statistics from the Coldcard Sweep Watch dashboard, as of August 3, the number of stolen Bitcoins had risen to about 1,366, worth nearly $90 million, making it the largest Bitcoin theft incident of the year. There is also a suspected fourth wave of attacks ongoing, and the loss figures are still rising.

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

What is the Vulnerability

Specifically, when users create a wallet on Coldcard, the device generates a random number, which is the seed. All subsequent private keys and addresses are derived from it. This seed must be sufficiently random and unpredictable; otherwise, once it is calculated by someone, the assets in the wallet lose their protection.

To achieve this, hardware wallets typically include a dedicated hardware true random number chip that generates unpredictable random values from physical noise.

The problem lies precisely in this aspect.

According to an incident report from Block Engineering, during a code migration in March 2021, a judgment in the firmware was written incorrectly, causing the device to not actually call the hardware random number chip when generating the seed, but instead quietly reverted to a software pseudo-random scheme. The initial input for this scheme consisted of publicly available or predictable values like chip numbers and timer readings.

As a result, the seed was no longer an unpredictable random number but became a result that could be reverse-engineered according to a fixed pattern. Attackers could enumerate a large number of possible seeds offline using the same logic, calculate the corresponding addresses, and then compare them with publicly available addresses on the blockchain. Once matched, it equated to obtaining the private key, allowing them to directly transfer the coins.

The severity of the vulnerability depends on the device model. According to Coinkite's estimates, for the most severely affected Mk3 model, effective randomness collapsed from the expected 128 bits to about 40 bits; Mk4, Mk5, and Q models, due to additional random values mixed in from a security chip, had about 72 bits. Regardless of the model, this is far below the strength required for security, making it feasible to exhaustively break with modern computing power.

Exaggeratingly, this vulnerability had existed in the publicly available firmware code since March 2021, spanning multiple versions, and silently persisted for more than five years until it was massively exploited on July 30, 2026.

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

However, not all Coldcard users are at risk. Coinkite stated that adding at least 50 independent private dice rolls when generating the seed or setting a sufficiently strong passphrase significantly reduces risk; additionally, the company's Satscard, Opendime, and Tapsigner are not affected by this vulnerability due to their use of different codebases.

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

From Theft to Recovery, the Incident is Still Evolving

According to tracking by Galaxy Research, the attacks unfolded in three waves.

  • The first wave occurred on July 30, with 1,195 addresses completely emptied, approximately 1,082.65 BTC stolen;
  • The second wave on July 31 involved 1,478 addresses;
  • The third wave on August 1 involved 1,912 addresses.

Notably, the first wave of attacks occurred about 30 hours before Coldcard officially issued a warning. This means that many users had their funds transferred before receiving the alert.

Currently, a suspected fourth wave of attacks is ongoing, with preliminary estimates of about 449 BTC, and the loss amount is still increasing.

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

The incident quickly spilled over to the blockchain and the market.

Firstly, there has been a change in the flow of funds. After the collapse of FTX in 2022, investors had withdrawn large amounts of cryptocurrency from exchanges, turning to hardware wallets and other self-custody solutions; this time, there are signs of Bitcoin flowing back to exchanges.

Data disclosed by CryptoQuant's research director Julio Moreno shows that the number of on-chain small transfers of less than 1 BTC has risen to the highest level since November 2022, with approximately 39,600 BTC transferred in a single day, only about 300 BTC lower than the record set just days after FTX filed for bankruptcy.

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

Bitcoin's price has also weakened since July 31, falling from around $65,000 to about $63,000.

Secondly, several noteworthy details have emerged regarding the whereabouts of the stolen funds and recovery efforts.

Tracking by Galaxy Research shows that nearly all of the stolen Bitcoins are still sitting in addresses controlled by the attackers and have not yet entered exchanges or mixing services, which is why there is still a window for recovery.

However, the attack methods have been upgraded: in the first two waves, funds were consolidated into a few addresses, making them traceable on-chain; while the third wave used 293 one-to-one transfer links, with each stolen wallet corresponding to a brand new address that did not share consolidation points, making on-chain detection more difficult.

During the recovery process for the stolen funds, Galaxy research director Alex Thorn revealed that one victim holding nearly 30 Bitcoins had 17 of them exchanged for ETH and deposited into the entertainment platform Duel. The victim had emailed the platform requesting to freeze the funds, but they were ultimately transferred out before the freeze could be implemented.

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

Thorn also stated that attacks surrounding Coldcard are still ongoing, with more small attackers and imitators emerging, targeting the remaining Coldcard mnemonic phrases.

Thirdly, there has been a response from manufacturers. Coinkite stated that the past three days have been one of the most challenging periods in the company's history, with the team continuously contacting customers and assisting in transferring still-safe funds since last Friday. The official has destroyed the remaining inventory produced using the vulnerable firmware and suspended shipments, while reminding users that updating the firmware cannot fix the old seeds that have already been generated; affected users need to create new wallets and transfer their funds.

However, some users have reported that after installing the update, their devices remained stuck on error pages, could not start, or appeared to be bricked, mainly involving Mk4 and Q devices.

Is Self-Custody Still Worth It?

This vulnerability has significantly impacted trust in self-custody.

Binance founder Changpeng Zhao stated that in a self-custody model, even if developers fix the vulnerability, they cannot fix wallets that have already been generated; for users with isolated devices, developers also cannot directly contact them to warn them, and until users take proactive measures, the relevant wallets may continue to be exposed to risks. He expressed his support for self-custody, but this also means that the security responsibility falls on the users themselves.

Bloomberg ETF analyst Eric Balchunas pointed out that the Coldcard team consists of only about five employees, which is too low for such an important company, and questioned whether users are willing to entrust their life savings to a company with only five people. He believes that larger institutions may have advantages in security investments, and Bitcoin ETFs provide another option.

Additionally, the proliferation of AI tools has made the implications of this incident even more complex.

Some developers claimed to have used Claude Code to scan the Coldcard open-source firmware for vulnerabilities, pinpointing the core issue in about eight minutes; other community users reported that they independently scanned with Zhizhu GLM 5.2 and also discovered the vulnerability.

Coinkite stated that the company had also reviewed the code with the top AI model at the time a few weeks ago but did not find the vulnerability, speculating that the attackers might have used AI to review the old version of the open-source firmware.

In an effort to restore industry reputation, Bitgo CEO Mike Belshe deposited 100 BTC into a public Bitcoin address on August 1 and invited the Claude model from Anthropic to attempt to transfer the funds from that address.

Coldcard stolen for over 100 million dollars, when cold wallets are not safe either

Strive Vice President Joe Burnett stated that this could be one of the worst weeks in Bitcoin history. Many people purchased recognized hardware wallets, generated mnemonics offline, and followed established best practices, yet still suffered significant losses due to this vulnerability. In his view, this will change people's confidence in self-custody. Self-custody will not disappear, but for those who wish to directly control a large amount of Bitcoin, the standard should be upgraded to multi-vendor multi-signature. Users who cannot accept this complexity should turn to institutional-grade custody.

In fact, security issues with hardware wallets are not unprecedented. However, past attacks mostly required physical contact with the device or tampering in the supply chain, which had high barriers and was difficult to scale; this time, it was entirely accomplished through software, remotely, and could be automated in bulk.

Institutional custody is also seen as potentially leading to excessive Bitcoin concentration in large companies, bringing risks of censorship, seizure, and confiscation.

From this perspective, the issue of fund security seems to lack a standard solution. As for the future of self-custody, it is being re-examined by an increasing number of people.

Join ChainCatcher Official
Telegram Feed: @chaincatcher
X (Twitter): @ChainCatcher_
warnning Risk warning
app_icon
ChainCatcher Building the Web3 world with innovations.