Skip to content

Coldcard Wallet Hack Grows to $89M After Third Wave of Sweeps

Coldcard Wallet Hack Grows to $89M After Third Wave of Sweeps

Short answer: On August 2, 2026, Galaxy Research reported a third wave of thefts from Coldcard hardware wallets, lifting the total drained to about 1,367 BTC (roughly $89 million) from 4,585 bitcoin addresses. The Coldcard wallet hack exploits weak seeds created by a 2021 firmware bug, so updating the device does not help: affected users have to generate a new seed and move their coins.

What happened

Coldcard is a bitcoin-only hardware wallet made by the Canadian company Coinkite. Since July 30, 2026, attackers have been quietly sweeping coins from addresses whose keys were generated on the device. Galaxy Research, the research arm of Galaxy Digital, has tracked the thefts on-chain and grouped them into three waves.

WaveWhen (UTC)BTC takenAddresses
FirstJuly 30, in 41 minutes1,082.65 BTC (about $70M)1,196
SecondAfter July 30Smaller, mid-sized balancesNot separately reported
ThirdMidday July 31 to morning August 1About 208 BTC1,912
Total so farAs of August 2About 1,367 BTC (about $89M)4,585

The third wave changed pattern. The first sweep took about 1 BTC per victim; the third averaged roughly 0.1 BTC, sent each victim's coins to a separate destination address and bundled about six victims per transaction. Galaxy says each wave looks like the work of a single operator but cannot confirm that the same attacker ran all three. On August 2, Galaxy head of research Alex Thorn urged anyone holding coins on Coldcard-generated addresses to move them immediately.

How the Coldcard exploit works

A wallet seed is only as safe as the randomness used to create it. In a March 2021 firmware release, an integration error made Coldcard devices generate seeds with a predictable software pseudorandom number generator instead of the hardware random number generator on the device's STM32 chip. The result is far less entropy than the 128 bits a 12-word seed is supposed to carry:

  • Mk3: as little as about 40 bits of effective entropy.
  • Mk4, Mk5 and Q: about 72 bits.

With that little randomness, an attacker can recreate the possible seeds offline, derive the private keys and spend the coins. No device is touched and nothing is phished: on-chain, the theft looks exactly like an owner moving their own funds, which is why it went unnoticed until the first large sweep. Galaxy has reported about 600 suspected attacker addresses to federal investigators.

Which Coldcard wallets are affected

Coinkite published an advisory and shipped emergency firmware for every affected model on July 31. Chief executive Rodolfo Novak apologised the same day and said the company takes full responsibility for the bug.

ModelVulnerable firmwareFixed in
Mk2 / Mk34.0.1 to 4.1.94.2.0
Mk4 / Mk5Before 5.6.0 (Edge: before 6.6.0X)5.6.0 / 6.6.0X
QBefore 1.5.0Q (Edge: before 6.6.0QX)1.5.0Q / 6.6.0QX

TAPSIGNER, OPENDIME and SATSCARD are not affected. The key point is that the patch fixes future seed generation only; a seed already created on vulnerable firmware stays weak forever. The exception, per Coinkite, is a seed created with at least 50 independent, private dice rolls. A strong, unique BIP-39 passphrase adds protection, but Coinkite still recommends migrating.

What it means for you

If you own a Coldcard, treat this as urgent but do it calmly: a rushed migration to a badly recorded seed is its own risk. Coinkite's recommended order is roughly this:

  1. Update the firmware to the fixed version for your model.
  2. Generate a brand-new seed on the updated device, ideally adding your own dice rolls.
  3. Write the backup down carefully and verify it.
  4. Check the new receive address on the device screen and send a small test transaction.
  5. Only then move the rest of the funds to the new wallet.

Single-signature wallets created on affected firmware are the most exposed. Expect elevated bitcoin network fees while thousands of users migrate at once; our guide to crypto network fees explains how to set them. Watch for phishing, too: no manufacturer will ever ask for your seed words, whatever the emergency.

Key takeaways

  • Coldcard wallet hack losses reached about 1,367 BTC (about $89 million) across 4,585 addresses by August 2, 2026.
  • The cause is a March 2021 firmware bug that generated seeds with weak, predictable randomness.
  • New firmware stops new weak seeds but cannot repair existing ones.
  • Affected users should create a new seed and move their coins; seeds made with 50+ dice rolls are the exception.

For a broader checklist on backups, passphrases and address checks, see our crypto wallet security guide.

Sources: CoinDesk, Coinkite, The Hacker News, CoinMarketCap

Frequently asked questions

Is my Coldcard wallet affected by the hack?

It is at risk if its seed was generated on Mk2 or Mk3 firmware 4.0.1 to 4.1.9, Mk4 or Mk5 firmware before 5.6.0, or Q firmware before 1.5.0Q (Edge builds before 6.6.0X and 6.6.0QX). Seeds created with at least 50 private dice rolls are not affected.

Does updating Coldcard firmware protect my bitcoin?

No. The update only makes new seeds safe. If your seed was created on vulnerable firmware, you need to generate a new seed and move your coins to it.

How much bitcoin was stolen in the Coldcard hack?

As of August 2, 2026, Galaxy Research counted about 1,367 BTC, roughly $89 million, taken from 4,585 addresses in three waves since July 30.

← Blog

Read next