Cut Through CryptoBetaSubscribe
Latest of 4
Coldcard Exploit Tops $88M

Coldcard Exploit Tops $88M

Verified · 3 Aug 2026BitcoinAug 3, 2026

Galaxy Research's Alex Thorn flagged a suspected fourth wave of Coldcard thefts on August 3 — around 449 BTC from roughly 709 addresses and still climbing — on top of the roughly 1,367 BTC (~$88.6 million) from 4,585 addresses across three earlier waves, all tied to a March 2021 firmware flaw that generated guessable seeds. Thorn characterised the newer sweeps as likely copycats exploiting the public flaw, and noted some transactions remain unconfirmed, giving affected users a narrow window to rescue funds via higher-fee replacement transactions. Coinkite halted shipments, destroyed vulnerable stock, and urged immediate migration; Bloomberg analysts questioned whether a roughly five-person team can carry the security load, per coverage.

Coldcard: you didn't remove the middleman. You shrank him.

The uncomfortable number here isn't the $88 million. It's five.

That, Bloomberg analysts noted this week, is roughly how many people work at Coinkite — the firm behind Coldcard, a hardware wallet whose entire promise is that it, and it alone, spins the random words your whole stack hangs on.

Here's the thing self-custody was supposed to fix. You hold your own keys so you don't have to trust an exchange with your money. But every one of those keys was born from one company's code getting one thing right, once, on a device you can't see inside. Thousands of people who left the exchange to escape trusting strangers ended up trusting a different, smaller set of strangers — ones they never met, running code they never read, whose single mistake in 2021 is being harvested right now.

That's not an argument for going back to exchanges. It's the point everyone skips: self-custody doesn't delete the middleman. It shrinks him until he's easy to forget. The Coldcard holders who came through fine are the ones who never forgot — who added a passphrase, rolled their own dice, split across keys, and refused to let any one maker's promise be the whole of their security. The lesson of the week isn't "trust hardware" or "trust exchanges." It's trust no single thing, however small it has shrunk.

Multi-media snippets

Cold Card Bitcoin wallet firmware bug exposes 100 million in stolen Bitcoin

CryptosRUs

New Coldcard firmware reportedly bricking devices, raising suspicion about covering tracks

Bitcoin University

Node operators should disable RBF to protect Coldcard multisig users from transaction sniping

Bitcoin University

Attackers can steal Coldcard multisig funds by observing public keys revealed in unconfirmed transactions

Bitcoin University

Coldcard founder NVK accused of lying about customer data deletion

Bitcoin University

Recommended actions for Coldcard users: move funds to alternative wallets

Bitcoin University

Coldcard hardware wallet seeds generated with insufficient randomness compromise all user funds

Bitcoin University

Crowder theorizes Coldcard attack may be state-level operation timed before BIP 110 soft fork

Bitcoin University

Coldcard victims should retain devices as evidence for legal proceedings

Bitcoin University

Coldcard wallet drains allegedly stem from years-old randomness flaw

Bitcoin University

Jonathan Goodman lost $1.6 million in Bitcoin from ColdCard vulnerability despite proper security practices

Digital Asset News

ColdCard hack has resulted in approximately $80-85 million in stolen Bitcoin as of July 29-30, 2024

Digital Asset News

ColdCard MK3 firmware vulnerability exposed weak random number generation in seed phrases

Digital Asset News

AI models demonstrate capability to find crypto vulnerabilities and break security

CryptosRUs

Related storylines

45 sources