A {hardware} pockets is meant to be the one place a hacker can’t attain. That assumption broke on July 30, 2026, when an attacker emptied greater than 1,000 Bitcoin from Coldcard wallets without ever touching a single device. The running total has already passed $70 million, drained from 1,196 wallets in a 41-minute span, and analysts say it is still rising.
A March 2021 firmware bug sat in plain sight for years
Coldcard, built by Canadian firm Coinkite, generates the seed phrase that controls your coins. A firmware update shipped in March 2021 broke the check meant to switch on the device’s hardware random number generator. The software quietly fell back to a predictable substitute seeded by the chip’s serial number and internal clock.
The result: Mk3 seeds carried roughly 40 bits of entropy instead of the 128 bits a Bitcoin seed should have. Mk4, Mk5, and Q devices landed around 72 bits, which is better, but Coinkite still called it serious.
How $70 million left wallets no one touched
Because the seeds were guessable, the attacker never needed the hardware. They generated candidate seeds on their own machine, derived the addresses each would produce, and checked those against the public blockchain. The victim’s Coldcard could have been switched off in a safe on another continent.
The sweep ran for about 41 minutes early on July 30. Galaxy Research first mapped 1,082.65 BTC across 1,196 addresses, then flagged a second wave that lifted the tally past $75 million. Oddly, none of it has moved, the coins sit unspent across a handful of attacker addresses.
Which Coldcard owners are exposed, and what Coinkite says to do
Every drained wallet was single-signature and created after the March 2021 firmware release, the strongest link between the thefts and the bug. Owners who added a BIP-39 passphrase or rolled at least 50 dice during setup are safe, since that fed in randomness the attacker can’t rebuild.
Coinkite pushed emergency firmware on July 31: 4.2.0 for Mk3, 5.6.0 for Mk4 and Mk5, and 1.5.0Q for Q. Updating the firmware does not change or repair an existing seed. Affected users have to generate a fresh seed on fixed firmware and move their funds over.
What the Coldcard hack means for Bitcoin self-custody
The timing stings. Blockaid reported that crypto losses topped $1 billion in the first half of 2026, most of it from compromised keys and operational slips rather than smart-contract exploits. Its CEO, Ido Ben-Natan, said Coldcard fits that pattern, with the exposure starting at the key-generation stage.
It reopens the debate that followed the $1.5 billion Bybit heist: holding your own keys removes exchange risk but hands you every other risk. Some analysts expect skittish holders to lean toward regulated custodians and spot Bitcoin ETFs, which saw heavy outflows as the news spread and BTC slipped about 3%. For anyone weighing the trade-offs, the self-custody options now offered by mainstream players carry a sharper warning label than they did a week ago.
Author: Ayanfe Fakunle
The editorial team at #DisruptionBanking has taken all precautions to ensure that no persons or organizations have been adversely affected or offered any sort of financial advice in this article. This article is most definitely not financial advice.
See Also:
Korbit Sells 15 BTC and 60 ETH as Korean Trading Volume Drops 89% | Disruption Banking













