Coldcard Hardware Wallet Hack Drains Over $116 Million in Bitcoin

A firmware bug that sat unnoticed for five years just became one of the biggest hardware wallet failures in crypto history.
Hackers have stolen more than $116 million in Bitcoin by exploiting a flaw in Coinkite’s Coldcard hardware wallet, a device long marketed as one of the most secure ways to hold Bitcoin offline. The vulnerability traces back to a March 2021 firmware release containing a build configuration error that caused affected devices to generate wallet seeds using a weak software random number generator instead of the device’s dedicated hardware entropy source.
Since the exploit began on July 30, attackers have hit more than 5,200 individual wallet addresses across four separate waves of theft. Blockchain intelligence firm Galaxy Research has tracked roughly 1,816 Bitcoin, worth close to $116 million, moving off compromised wallets, though some estimates of total losses run as high as $130 million.
What makes this particularly damaging is how the flaw undermines the entire premise of a hardware wallet. Predictable seed generation means an attacker who identifies the pattern can potentially reconstruct a wallet’s private keys without ever touching the physical device or tricking its owner — the opposite of the phishing or malware-driven thefts that account for most crypto losses.
At least a dozen different hacking groups appear to be exploiting the same underlying bug independently, suggesting the vulnerability became widely known or reverse-engineered within the attacker community rather than being exploited by a single sophisticated actor.
Coinkite confirmed the vulnerability, halted all shipments of the affected units, and said it has destroyed remaining inventory manufactured with the flawed firmware. The company has not yet detailed a full remediation plan for existing owners of affected devices.
The incident adds to what is already a record year for crypto security failures, with total losses across the industry surpassing $1.2 billion across more than 275 incidents in 2026 alone — a reminder that even offline, air-gapped storage is only as secure as the software that generated the keys in the first place.
Want to understand how hardware wallets generate and protect private keys? Learn more in the Bitcoin Academy.
