Firmware Bug Dormant for Five Years Drains $116 Million in Bitcoin From Coldcard Wallets
A single misconfigured software setting in a widely trusted Bitcoin hardware wallet exposed more than 5,200 wallet addresses to remote theft, costing holders an estimated $116 million to $130 million over five days of attacks beginning July 30.
The exploit targeted Coldcard hardware wallets running firmware version 4.0.1, released by Toronto-based manufacturer Coinkite in March 2021. A build flag that should have activated the device's onboard hardware random number generator was set to zero, silently forcing the wallet to use a far weaker software alternative instead. Specifically, the flaw bypassed the STM32 chip's hardware RNG and substituted MicroPython's Yasmarang pseudo-random number generator (PRNG) in its place. Because Bitcoin private key security depends entirely on the unpredictability of the seed generation process, the substitution gutted the intended 128-bit entropy down to roughly 40 bits on older Mk3 devices and about 72 bits on newer Mk4, Mk5, and Q models. According to Block's security research team, the Mk3 reduction left only around one trillion possible seed combinations, a pool that modern GPU clusters can exhaust within hours.
The first wave struck at approximately 2:14 a.m. UTC on July 30. Blockchain forensics firm TRM Labs recorded 594 BTC drained from roughly 500 addresses in about 25 minutes. Every transaction in that wave carried a uniform fee of 30 satoshis per virtual byte, a detail consistent with a single coordinated operator running automated tooling. Three additional waves followed over the next five days, widening the victim pool to more than 5,200 addresses. By Wave 3, cumulative losses reached 1,367 BTC across 4,585 addresses. TRM Labs estimates that a fourth wave added approximately 2,055 BTC from 709 addresses through early August, though those figures remain preliminary. TRM Labs noted limited mixing activity, describing it as exploratory rather than aggressive, and said the attack pattern does not match known state-sponsored groups. As of August 7, roughly 90 percent of stolen funds remain at attacker-controlled addresses, with only 64.9 BTC routed through privacy mixer Wasabi and approximately 200 ETH sent through Tornado Cash. That ETH figure reflects a portion of the stolen Bitcoin that the attacker appears to have converted to Ether before routing through the Ethereum-based mixer.
Coinkite released an emergency firmware patch on July 31, but the fix cannot undo past damage. Any seed phrase generated between March 2021 and the patch deployment is considered permanently compromised. The company's CEO, NVK, was direct about the required response: "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices." He also suggested that AI-powered code analysis tools may have been what identified the flaw, raising a broader concern that open-source firmware repositories can now be scanned for exploits faster than human security reviewers can audit them.
The incident drew sharp responses across the industry. Bitcoin commentator Guy Swann called it "the worst hit in Bitcoin history to the most knowledgeable and 'properly secured' bitcoiners." David Lawrence, co-founder of custody firm Amicus, offered a starker assessment: "The vision of 8 billion people holding Bitcoin in cold storage is essentially over." Nick Neuman, CEO of multisig custody firm Casa, pointed to a structural problem: "You just can't ask people to roll dice to be secure with your self-custody. It is a non-starter for 99 percent of people." Lorenzo Valente, Director of Digital Asset Research at ARK Invest, framed the tradeoff bluntly: "Consumers have traded counterparty risk for software risk, hardware risk, supply-chain risk, phishing risk."
The geographic footprint of losses reflects where Coldcard's technically sophisticated user base was concentrated. Among the confirmed victims is Tim Lamb, profiled by the Japan Times, who lost 2 BTC (approximately $130,000) while on vacation in the Channel Islands. Canada, home to Coinkite's headquarters, accounted for roughly 25 percent of losses. Australia followed at 15 to 20 percent. The United States and Thailand each saw 10 to 15 percent of confirmed losses. Western Europe recorded significant losses, and Latin America reported damages as well, though neither region has released precise figures. Nigeria and South Africa were also confirmed as affected markets. For users in sub-Saharan Africa, the implications cut deeper than the dollar figures suggest. In Nigeria, many Bitcoin holders specifically chose self-custody to avoid frozen exchange accounts, a concern rooted in a 2021 central bank ban on crypto-related banking. The same logic applied in South Africa, where Coldcard's reputation among technically literate users made it a default choice after the FTX collapse. In both cases, the tool selected to avoid institutional risk became the attack surface itself. Analysts at Verse Press note that in South Asia, where India ranks first globally on the Chainalysis 2025 Crypto Adoption Index and Pakistan sits in the top five for peer-to-peer volume, hardware wallets often serve as a hedge against capital controls and currency instability rather than a speculative accessory. Bangladesh, where formal crypto regulation remains thin and individuals bear the full burden of custody, faces similar exposure. Losses in these markets may be proportionally more severe given lower average holdings and fewer regulated fallback options.
TRM Labs ranked the event as the third-largest crypto hack of 2026. Year-to-date losses across the industry have now exceeded $1.2 billion across 276 incidents. "Token flows to custodians and exchanges will increase following the hack," said Nico Pasquariello of Cantor Fitzgerald, whose firm named Coinbase (COIN), Robinhood (HOOD), BitGo Holdings (BTGO), Bullish (BLSH), eToro Group (ETOR), and Gemini Space Station (GEMI) as likely beneficiaries of increased institutional custody demand. On-chain data already reflects the shift: net Bitcoin transfers from self-custody wallets to exchanges turned positive after July 31 for the first time since the FTX collapse in November 2022, with OKX reporting record inflow levels. Whether that trend holds will depend partly on whether Coinkite can rebuild trust and, analysts suggest, whether the incident prompts regulators in the EU, India, and elsewhere to establish formal standards for hardware wallet manufacturers.