Coldcard Hack: what happened and how to protect yourself
A vulnerability in the Coldcard (Coinkite) firmware weakened the random number generator used to create certain seed phrases, allowing attackers to reconstruct private keys and steal approximately 1,367 BTC (nearly $89 million) from over 4,500 addresses, without physical access to the devices. Mk3 models running firmware 4.0.1 to 4.1.9 are formally affected.
A hardware wallet is supposed to be the safest place to store Bitcoin. This very premise has been shaken by a recent incident: since late July 2026, a firmware vulnerability in the Coldcard, manufactured by the Canadian company Coinkite, has enabled the theft of tens of millions of dollars, without ever requiring physical access to the devices.
What happened?
Starting July 30, 2026, several waves of coordinated attacks targeted Bitcoin wallets generated on Coldcard wallets. A first wave allowed approximately 594 BTC (nearly $38 million) to be stolen in just 25 minutes, from approximately 500 addresses.
Subsequent waves, documented by blockchain research firm Galaxy Research, pushed the total to approximately 1,367 BTC, or nearly $89 million, stolen from over 4,500 addresses. Some broader estimates even suggest over $100 million across several thousand accounts in total.
This is one of the largest documented thefts ever from "cold storage" devices, which are usually considered the safest method for storing cryptocurrencies.
What caused this vulnerability?
According to published technical analyses, notably by Block's engineering team, the root of the problem dates back to a code modification made in March 2021. This change caused a silent switch in the random number generator on certain devices: instead of using the hardware generator designed to create the seed phrase — which was supposed to produce 128 bits of entropy, a level of randomness making any attempt to guess the key practically impossible — the firmware started using a much weaker software generator.
On Coldcard Mk3 devices, this vulnerability reportedly reduced the effective search space to only about 40 bits, a level much more accessible to computation, allowing an attacker to reconstruct certain seed phrases and steal the corresponding funds — without ever needing physical access to the victim's device. Coinkite has confirmed the existence of this vulnerability, while specifying that the 40-bit estimate remains preliminary at this stage of the investigations.
Which devices are affected?
Based on information available to date:
- Coldcard Mk3 devices that ran firmware versions 4.0.1 to 4.1.9 are formally identified as vulnerable.
- As a precaution, Coinkite has also released patches for Mk4, Mk5, and Q models, without confirmation that they are affected in the same way.
- What matters is not the firmware version currently installed, but the version used at the time the seed phrase was generated — updating your firmware now does not fix an already compromised seed created on a vulnerable version.
A notable point raised by several researchers: users who used an external entropy source when setting up their wallet (a method sometimes called "roll your own dice," consisting of generating part of the randomness oneself, for example with physical dice) were not affected by this vulnerability, as their seeds remained unpredictable for attackers.
What this incident changes (and doesn't change) about self-custody
This event has reignited the debate on the reliability of self-custody versus delegated custody solutions (regulated exchanges, spot Bitcoin ETFs). However, several security experts, including Blockaid, point out an important contextual element: in the first half of 2026, the majority of cryptocurrency losses in the industry already stemmed from compromised keys and operational security errors, rather than smart contract vulnerabilities or exchange hacks. The Coldcard case fits into this broader trend.
This incident does not demonstrate that self-custody is riskier than leaving your crypto on an exchange — it illustrates a different category of risk, specific to hardware.
Security researchers emphasize this point: it is a risk related to the integrity of the firmware and the supply chain, rather than a counterparty risk or the solvency of a centralized platform. A hardware wallet remains, in principle, more secure than online storage — provided its design and firmware are irreproachable.
What to do if you own a Coldcard?
If you are affected, here are the actions recommended by security experts:
- Check the firmware version used at the time your seed was created, not just your current version.
- Don't panic, but act quickly: transfer your funds to a new wallet, with a seed generated on corrected firmware.
- First send a small test transaction before transferring all your funds, carefully verifying the destination address.
- Consider all addresses generated by the same device as potentially compromised — a single Coldcard often generates multiple accounts.
- Remain vigilant against opportunistic scams that typically arise after highly publicized incidents of this type (fake technical support, fake "fund recovery" tools).
- For complex configurations (multisig, large amounts), it may be relevant to seek professional crypto security assistance.
How to limit this type of risk in the future
This incident highlights several best practices applicable to any hardware wallet, regardless of the manufacturer:
- Keep your firmware updated, as patches released by manufacturers specifically address this type of known vulnerability.
- Prefer devices whose randomness generation relies on a certified hardware chip (EAL standard), audited by independent security laboratories.
- Consider a multisignature configuration for large amounts, distributing the risk across multiple devices or parties.
- Purchase your hardware exclusively from official distributors, to guarantee the authenticity and traceability of the device.
It is important to specify that Coldcard is not a product distributed by Neowalt. Our selection of hardware wallets is limited to the Tangem, CoolWallet, ELLIPAL, SafePal, and Keystone models, each sourced directly from its manufacturer, with EAL certified secure chips and authenticity guarantee. Find them all in our comparison of the best hardware wallets 2026.
FAQ: Coldcard hack
What is the Coldcard hack?
It is a firmware vulnerability in the Coldcard hardware wallet, manufactured by Coinkite, that allowed one or more attackers to reconstruct seed phrases and steal Bitcoin, without physical access to the affected devices.
How much money was stolen in the Coldcard hack?
According to the latest estimates, approximately 1,367 BTC (nearly $89 million) were stolen from over 4,500 addresses, with some broader estimates suggesting over $100 million in total.
Is my Bitcoin safe if I have another hardware wallet?
This vulnerability is specific to Coldcard's firmware. It does not affect other hardware wallet manufacturers, but it highlights the importance of keeping firmware updated and choosing a device whose key generation relies on a certified secure chip.
What to do if my Coldcard is affected?
Transfer your funds to a new wallet with a seed generated on corrected firmware, first testing with a small amount, and consider all addresses generated by the device as potentially compromised.
In summary
The Coldcard hack reminds us that a hardware wallet is only secure if its software design is also secure. Unlike an exchange hack, this incident does not illustrate a counterparty risk, but a technical risk related to firmware and key generation. It does not challenge the principle of self-custody, but emphasizes the importance of choosing reliable, up-to-date hardware purchased from guaranteed sources.
This article is for informational and educational purposes only. It does not constitute financial, legal, or investment advice in any way.
Ready to secure your cryptocurrencies?
Discover our comprehensive comparison and find the hardware wallet suited to your strategy, with an EAL certified secure chip.
Open the comparison tool