Share via:
- Updated on: August 12, 2026
In this article:
- A firmware bug let Coldcard hardware wallets generate weak, guessable seed phrases instead of properly random ones, letting attackers crack private keys and empty wallets that were never even connected to the internet.
- The bug shipped in firmware released from March 2021 onward and went unnoticed for roughly five years.
- Attackers have stolen more than 2,000 BTC, around $130 million, in several waves since July 30, 2026, and most of it is still sitting untouched in their wallets.
- If you generated a seed on affected firmware, updating alone will not protect you. You need to generate a brand-new seed and move your funds.
- This is still happening. Multiple attackers are involved, and unpatched wallets remain at risk.
What was the Coldcard vulnerability?
The Coldcard vulnerability was a random number generator flaw in the wallet’s firmware that made seed phrase generation predictable. Instead of drawing entropy from the device’s hardware random number generator, affected units silently fell back to a weak software substitute built from predictable device data.
Here is what went wrong, in sequence:
- During a 2021 migration between software libraries, two random-number functions with matching interfaces were confused for one another.
- A configuration setting was present in the build but disabled, causing seed generation to silently fall back to the software path — with no error, no warning, and no visible difference to the user.
- That fallback derived its randomness from predictable device information, including a chip identifier similar to a serial number and internal clock values tied to startup timing.
- The result was a drastically reduced keyspace. Attackers could crack the seed phrases and reconstruct private keys without ever touching the device or the owner’s network.
Effective entropy by device
Device | Effective entropy | Expected for a 12-word seed |
Coldcard Mk3 | ~40 bits | 128 bits |
Coldcard Mk4 | ~72 bits | 128 bits |
Coldcard Mk5 | ~72 bits | 128 bits |
Coldcard Q | ~72 bits | 128 bits |
To put 40 bits in context: that is a keyspace of roughly a trillion possibilities — small enough to search exhaustively with modest computing resources. The security model of a hardware wallet assumes the seed is unguessable. Here it was guessable, which is why air-gapping provided no protection whatsoever.
Coinkite published a security advisory on July 30, 2026 (updated August 1) acknowledging the flaw. The advisory states plainly that “updating the firmware does not change or repair an existing seed” and that version 4.2.0 “cannot repair a seed that was already generated by affected firmware.” CEO Rodolfo Novak also apologized publicly. Coverage of his remarks varies by outlet, and we have not been able to verify a single, consistent direct quote on responsibility, so we are citing Coinkite’s own written advisory rather than a paraphrased quote.
Timeline
Date | Event |
March 2021 | Vulnerable firmware begins shipping following the library migration |
30 July 2026 | First mass sweep — 1,196 addresses drained in 41 minutes, taking 1,082.65 BTC (~$70.2M at the time) |
31 July 2026 | Coinkite CEO Rodolfo Novak publicly accepts responsibility. Early loss estimates around $38M |
3 August 2026 | Estimates revised sharply upward to ~$116M as more addresses are identified |
4 August 2026 | Totals pass $130M. Multiple independent attacker groups confirmed |
6–7 August 2026 | Galaxy Research verifies 1,596 BTC from ~7,300 addresses across three waves; a suspected fourth wave would take it to ~2,055 BTC. Laundering activity begins on one cluster |
10 August 2026 | Reported totals exceed 2,000 BTC. Exploitation of unpatched wallets continues |
A note on the numbers. Public estimates moved from $38M to over $130M in six days, and various outlets have cited $89M, $116M, $120M, and $130M at different points. This is normal for an incident where victim addresses are still being identified, but it means any figure needs an “as of” date attached. Every number in this post carries one.
Where the stolen bitcoin went
What is publicly known
The most striking feature of this theft is how little of it has moved.
- ~90% of the stolen bitcoin remained unmoved as of August 7, 2026.
- The largest attacker holds 1,159 BTC across seven addresses, which have not moved since the initial sweep. Investigators have not detected transfers from those addresses to exchanges, mixers or other obscuring services. A note as of publication: on August 7, 2026, news.bitcoin.com reported that the attacker holding the largest share of the theft had resurfaced to move roughly 30 BTC to a new wallet after weeks of dormancy, an early signal analysts read as possible cash-out preparation. It is not yet clear from public reporting whether this is the same seven-address cluster referenced above or a different one, so treat the “untouched” figures on this page as accurate as of the sweep date and re-verify current status before publishing.
- A separate, smaller attacker began laundering: roughly 64 BTC was routed to a mixer, with about 10 BTC mixed and about 54 BTC returned as change. The remainder was then split into outputs of roughly 7 BTC each for further mixing.
- Approximately 600 flagged addresses — confirmed attacker and victim addresses — have been shared with US law enforcement agencies, exchanges and cyber-investigation groups.
- Every laundering step so far remains visible on the public ledger.
Galaxy Research and Chainalysis have both published analysis of the attack waves.
Crystal’s tracing
Crystal traced the addresses drained in the attack back through their transaction history using Crystal Expert’s address-level connection analysis. A subset of them received small, dust-sized deposits, worth a fraction of a cent, from a Wasabi wallet cluster in the months before the theft. Those deposits arrived in irregular waves starting in December 2025 and continuing into 2026, and the same addresses that received them are the ones swept on July 30, 2026.
One possible read: whoever ran the attack may have used these dust deposits to flag or pre-identify vulnerable addresses months ahead of striking. That is a working theory, not a confirmed finding, and we have not ruled out coincidence or an unrelated dusting campaign. We are still quantifying how many affected addresses show the pattern and how closely it lines up with the four attack waves, and we will update this section once that analysis is complete.
Am I affected, and what should I do?
You are potentially affected if you generated a seed phrase on a Coldcard device running firmware released from March 2021 onward. The risk attaches to the seed, not the device.
Device | Fixed in | Known vulnerable |
Coldcard Mk3 | v4.2.0 and later | v4.0.1 – v4.1.9 |
Coldcard Mk4 | v5.6.0 and later | releases before v5.6.0 |
Coldcard Mk5 | v5.6.0 and later | releases before v5.6.0 |
Coldcard Q | v1.5.0Q and later | releases before v1.5.0Q |
The critical point most coverage buries
Updating your firmware does not make an existing seed safe. A seed generated under affected firmware is permanently weakened, regardless of what firmware the device runs afterwards. The weakness is baked into the seed itself.
Coinkite has been explicit that installing the patch “does not repair an existing seed”, and — the trap worth spelling out — “restoring the old seed to updated firmware or another wallet carries the weakness forward.” Moving a compromised seed to a brand-new device, or to a different wallet entirely, does nothing. The seed is the problem.
If you generated a seed on affected firmware:
- Update to patched firmware for your device model above.
- Generate an entirely new seed on the patched firmware.
- Move all funds to addresses derived from the new seed.
- Treat the old seed as permanently compromised. Never reuse it, and do not assume a low balance makes it safe — attackers swept roughly 7,300 addresses indiscriminately.
- Verify your new seed’s entropy source if your device offers dice-roll or user-supplied entropy.
Do not delay on the basis that your wallet has not been touched yet. Attackers are continuing to work through unpatched wallets, and roughly 90% of the already-stolen funds sitting still is evidence of patience, not of the attack being over.
What this means beyond Coldcard
This incident has already become a talking point in the wider debate about how bitcoin should be held. Forbes reported that in the days after the exploit, US spot bitcoin ETFs took in roughly $626 million in new inflows, and some industry voices are framing that as evidence that regulated custody is safer than self-custody. Others, including long-time self-custody advocates, argue the opposite: that a firmware bug in one vendor’s hardware wallet says nothing about self-custody as a model, and that concentrating assets with a small number of custodians creates its own risk.
Crystal doesn’t take a side in that argument, but we do have a relevant vantage point: we trace funds regardless of who holds them, whether that’s a self-custody wallet, an exchange, or a regulated custodian. What this incident actually shows is narrower than either side’s framing: the failure was in how one device generated randomness, not in the concept of holding your own keys. The bigger lesson for institutions evaluating custody options is to ask vendors specifically how they generate and audit entropy, rather than treating this as a referendum on self-custody itself.
FAQ
What is the Coldcard hack?
A firmware flaw in Coldcard hardware wallets caused seed phrases to be generated with far less randomness than intended, letting attackers crack private keys and drain wallets. The first mass theft occurred on July 30, 2026.
How much bitcoin was stolen in the Coldcard exploit?
Galaxy Research verified 1,596 BTC taken from approximately 7,300 addresses across three attack waves, with a suspected fourth wave bringing the total to roughly 2,055 BTC — around $130 million. Estimates rose from $38M to over $130M between 31 July and 4 August 2026 as more victim addresses were identified.
Which Coldcard devices and firmware versions are affected?
Firmware released from March 2021 onward across Mk3, Mk4, Mk5 and Q devices. Fixes shipped in Mk3 v4.2.0, Mk4 and Mk5 v5.6.0, and Q v1.5.0Q. Devices running Edge firmware need a different fix: v6.6.0X for Mk4/Mk5 and v6.6.0QX for Q, per Coldcard’s own security status page.
Does updating my Coldcard firmware protect me?
No. A seed generated on affected firmware is permanently weakened regardless of what firmware the device runs afterwards. You must generate a new seed on patched firmware and move your funds.
Was this because my wallet was connected to the internet?
No. The affected wallets were air-gapped. The weakness was in how the seed was created on the device, so no network exposure was needed for attackers to reconstruct the keys.
Has the stolen bitcoin been recovered or frozen?
As of August 7, 2026, roughly 90% of the stolen bitcoin had not moved, the largest attacker’s 1,159 BTC sat untouched across seven addresses, and about 600 flagged addresses had been circulated to law enforcement and exchanges. Crystal’s own tracing also found that a number of victim addresses received small dust deposits from a Wasabi wallet cluster in the months before the theft, a pattern that may point to advance targeting, though this is a working theory rather than a confirmed finding. One caveat: a report on August 7, 2026 described renewed movement of roughly 30 BTC by the attacker holding the largest share of the theft, so these figures should be re-verified against Crystal’s current tracking before this goes live.
Can the stolen funds be traced?
Yes. Every movement so far remains visible on the public ledger, including the mixing attempt on one cluster. Crystal Expert’s connection analysis is following the post-mix outputs now, and we will publish what that tracing shows, including where the trail holds and where it breaks down, once the analysis is complete.
Is the Coldcard exploit still ongoing?
Yes. Multiple independent attackers are involved and unpatched wallets remain exploitable, so owners who have not rotated their seeds are still at risk.
The bottom line
The Coldcard exploit is a reminder that a hardware wallet is only as secure as the randomness behind it. If you generated a seed on affected firmware, updating alone will not protect you: generate a new seed, move your funds, and treat the old seed as permanently compromised. With multiple independent attackers still working through unpatched wallets, this is not resolved yet.
Crystal is continuing to trace where the stolen funds go, including the patterns covered above, and we will update this page as the picture develops. For more on how incidents like this get traced on-chain, visit our investigations hub. If you work in compliance, investigations, or risk and want to see that same tracing capability applied to your own exposure, get a demo of Crystal Expert.
