A hardware wallet is supposed to be the one place a hacker can’t reach without physically touching it. That assumption broke on July 30, 2026, when an attacker drained over 1,000 Bitcoin from Coldcard wallets — without ever touching a single device.
💥 What Happened
Blockchain analytics firm Galaxy Research traced a coordinated sweep of 1,196 Bitcoin addresses in just 41 minutes, taking 1,082.65 BTC — worth approximately $70.2 million at the time. The running total has since climbed past $89 million as additional affected wallets came to light.
| Detail | Figure |
|---|---|
| Addresses drained | 1,196 |
| BTC stolen (initial estimate) | 1,082.65 BTC (~$70.2M) |
| Updated loss estimate | ~$89 million |
| Time window of attack | 41 minutes (July 30, 2026) |
| Root cause | March 2021 firmware integration error |
🔍 The Technical Flaw, Explained Simply
Coldcard, a Bitcoin-only hardware wallet made by Canadian firm Coinkite, is supposed to generate its seed phrase (the master key to your coins) using a true hardware random number generator. A firmware bug introduced in March 2021 accidentally routed seed generation through a predictable software-based number generator instead — one that could be reconstructed offline by an attacker who understood the flaw, without ever needing physical access to the device.
Once seeds were recreated as candidates, the attacker simply checked them against public blockchain data to identify which ones controlled real funds — then drained them, starting with the highest-value wallets first.
⚠️ Who Is Affected
Anyone who generated a Coldcard seed between March 2021 and the firmware fix is potentially at risk — even if the device has since been updated, because updating firmware does not retroactively fix a seed that was already generated insecurely. Coinkite CEO Rodolfo Novak posted a public apology, urging affected users to move funds immediately using updated best practices.
Notably, users who added a BIP-39 passphrase or rolled physical dice during setup for extra entropy are considered safe, since that additional randomness can’t be reconstructed by an attacker.
🛡️ What to Do If You Own a Coldcard
- Update to the latest firmware immediately (available for all affected models)
- If your seed was generated between March 2021 and now without a BIP-39 passphrase, treat it as compromised
- Move funds to a newly generated wallet — verify the new address carefully before transferring
- Never enter your existing seed phrase into any website or software during “recovery”
🔮 The Bigger Lesson
This incident is a reminder that “cold storage” security depends entirely on how the device generates randomness in the first place — a flaw invisible to the end user, who has no way of independently verifying that a hardware wallet’s random number generator is working as advertised.
Disclaimer: This article is for informational purposes only and does not constitute security or investment advice. If you own a Coldcard device, consult official Coinkite advisories and verified security researchers before taking action with your funds.
]]>






Leave a Reply