A $70 million cryptocurrency trading disruption has exposed a critical vulnerability in one of the industry’s most trusted security tools: the Coldcard hardware wallet. On July 30, 2026, attackers drained more than 1,000 bitcoin from 1,196 wallets over a 41-minute window, nearly double the initial reports, according to analysis by Galaxy Research.
The attack exploited a firmware flaw dating to March 2021 that weakened the randomness used to generate recovery seeds on certain Coldcard models. Instead of using a dedicated hardware randomness generator, affected devices fell back to a basic software substitute seeded from the chip’s serial number and clock registers—data an attacker could narrow down or measure on a device of their own.

What made this attack unusually significant was that the attacker never physically accessed any device. By reconstructing private keys offline and checking candidate addresses against the public blockchain, the operator could enumerate wallets systematically across three address formats—a pattern that Galaxy Research identified as a scanner searching comprehensively rather than targeting specific victims.
The attacker made one critical mistake: using a paid account at a blockchain data provider to query the source addresses during the sweeps. Block, a security firm, traced this activity with what its researcher Clay Garrett called “extraordinary specificity, down to the number, timing and sequence of requests.” Block has passed the information to authorities.
Coldcard maker Coinkite has acknowledged the bug, apologized, and released emergency firmware updates. The company advised users who generated seeds on affected versions—Mk2, Mk3, Mk4, Mk5, and Q models—to create entirely new seeds on patched devices and carefully migrate funds. Simply updating firmware does not secure an already-created vulnerable seed.

The incident has renewed debate over the limits of self-custody. Hardware wallets are widely viewed as one of the strongest options for securing bitcoin offline, yet the Coldcard case shows that even long-established devices can harbor critical flaws that remain undetected for years. Many of the drained wallets had sat dormant for years, their owners unaware of the risk.
Binance founder Changpeng Zhao acknowledged the broader lesson in a post on X. “Even hardware wallets can have bugs. Even old wallets (with long history) can have bugs,” he wrote. “How to mitigate? Split your funds in a few wallets maybe? This has a different set of risks. Nothing is 100%. Stay informed. Stay SAFU!” His call for wallet diversification reflects a shift in how security-conscious holders view asset protection: no single tool can guarantee complete safety.
The Coldcard exploit underscores a growing challenge in cryptocurrency security. As the cost of finding and exploiting flaws in key generation falls, storing a key safely has become only half the problem. The attack ran entirely on the attacker’s own hardware, making traditional distance-based defenses—the core promise of offline storage—ineffective against weaknesses in how keys are created in the first place.
Sources
- CoinDesk — technical details of the attack mechanism, Galaxy Research analysis showing 1,082.65 BTC from 1,196 wallets over 41 minutes, Block’s discovery of the attacker’s blockchain data provider account, and CZ’s statement on wallet diversification
- Galaxy Research — expanded scope of the theft and analysis of the systematic enumeration pattern across address formats
- Block — firmware flaw details dating to March 2021 and identification of the attacker’s mistake using a blockchain data provider
- Coinkite — acknowledgment of the bug and emergency firmware updates for affected models











