Hacker attacks on Coldcard hardware Bitcoin wallets have resulted in the theft of 1,755 bitcoins, valued at over $110 million at the time of the attack. The attackers exploited a critical flaw in the firmware code that had existed since March 2021, allowing them to predict private keys and gain access to funds.
Alex Thorn, head of research at Galaxy, warned on Monday, August 3, 2026, of a new phase of attacks. According to Galaxy Research data, the first wave was the fastest and most devastating: in just 41 minutes, hackers stole 1,083 bitcoins from 1,196 addresses. In total, 1,755 bitcoins were taken from over 5,000 addresses in that initial strike.
How the Flaw Occurred and What Went Wrong
Coldcard is a hardware wallet by Canadian company Coinkite, designed to securely store private keys offline. The problem arose in the device's firmware during private key generation. As explained by the specialized portal Numérama, a one-line code error caused certain devices to switch to a significantly weaker random number generator.
According to a security report by U.S. fintech firm Block, the consequence was that "seed phrases"-the 12 to 24 word recovery sequences-became predictable enough for skilled hackers to guess. This allowed them to steal funds without needing physical access to the device. According to Coinkite's statement, the flaw was introduced in March 2021.
Company Response and Call for Caution
On Sunday, August 2, 2026, Coinkite announced it had halted all shipments of Coldcard wallets as soon as the vulnerability was confirmed. "We stopped COLDCARD shipments as soon as we confirmed the vulnerability. All remaining units in our facility with affected firmware have been destroyed," the company said in a statement posted on X. For customers whose orders had already been shipped, the company reached out directly via email with instructions to migrate funds to a new, secure recovery phrase.
Coinkite also advises affected users to keep their wallets. "They could prove crucial if funds need to be recovered. Our legal team will, if necessary, coordinate efforts with law enforcement (...) to identify those responsible," the company stated. Their other products, such as Satscard, Opendime, and Tapsigner, use different codebases and are not affected by this vulnerability. The company also said it is in contact with "the entire hardware wallet community," including other developers and researchers, and issued an apology to its customers on Sunday.