BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Bitcoin

Coinkite Takes Full Responsibility for Coldcard’s $70…

How Much Bitcoin Was Drained From Coldcard Wallets? A vulnerability affecting seed generation on certain Coldcard hardware wallets has been linked to the theft of more than 1,000 Bitcoin, rai

AnonymousCryptoCompass newsroom
August 1, 2026
4 min read
NEWS
Hero article visual / chart / editorial image
CryptoCompass editorial visual for bitcoin coverage.

AFX Scrambles After $24M Hack Traced to One Dev

How Much Bitcoin Was Drained From Coldcard Wallets?

A vulnerability affecting seed generation on certain Coldcard hardware wallets has been linked to the theft of more than 1,000 Bitcoin, raising the estimated loss from the incident to about $70 million. Galaxy Research traced 1,082.65 BTC, valued at roughly $70.2 million, moving from 1,196 addresses during a 41-minute period on July 30. The affected wallets were completely drained between 01:10:20 and 01:51:26 UTC, based on a transaction pattern first identified by security engineers. The clustered timing and similar movement pattern indicated that the transactions were controlled by the same attacker. However, the research firm warned that the estimate may not capture every compromised wallet because malicious transfers are indistinguishable onchain from transactions authorized by their legitimate owners. “The nature of the vulnerability means that future attacks are possible on any Coldcard-generated address and those do not need to match this pattern,” Galaxy Research said. That means the final loss could rise if additional users discover unauthorized transfers or fail to move funds from vulnerable wallets.

Which Coldcard Devices And Firmware Are Affected?

Coinkite initially warned users who generated wallet seeds on a Coldcard Mk3 running firmware version 4.0.1, released in March 2021, or any later affected version. The hardware wallet manufacturer later expanded its advisory to include certain firmware versions used by the Mk4, Mk5 and Coldcard Q models. The problem concerns the generation of the seed phrase, the secret recovery information that controls access to a Bitcoin wallet. Updating firmware alone does not protect funds secured by a seed that may already be compromised because the original private keys remain unchanged. Coinkite released emergency firmware updates for the affected models and instructed users to create a new seed after installing the corrected software. Funds should then be transferred to addresses generated from the new seed rather than returned to an address associated with the old wallet configuration. Coldcard users should first test the replacement wallet with a small transaction. Once they confirm that the new wallet can receive and spend funds correctly, they can transfer the remaining balance. Coinkite advised retaining the old backup until the migration has been completed successfully.

Investor Takeaway

A hardware wallet protects assets only when its seed generation, firmware and backup process remain secure. Users of affected Coldcard versions may need to replace the seed itself, not simply install an update.

How Did Coinkite Respond To The Firmware Failure?

Coinkite CEO Rodolfo Novak apologized on Friday and said the company took “full accountability for the firmware bug.” He acknowledged that the firm’s internal review process had failed to identify the vulnerability before affected firmware was released to customers. The company’s admission places attention on testing standards at hardware wallet manufacturers. Unlike centralized exchanges, self-custody products place direct control of assets with users, but customers remain dependent on manufacturers to produce secure firmware and reliable random seed generation. A defect in that process can undermine the central protection offered by a hardware wallet. Even when the physical device remains in the owner’s possession and the seed phrase has never been shared, an attacker may be able to reconstruct wallet credentials if the generation method contains a predictable weakness. Novak suggested that artificial intelligence may have helped uncover the flaw, describing the incident as “a sober reality of the new AI paradigm.” Publicly available source code can now be reviewed more rapidly by both security researchers and attackers using automated tools capable of finding weaknesses that previously required extensive manual analysis.

What Does The Attack Mean For Hardware Wallet Security?

The incident shows that self-custody removes exchange counterparty risk but does not eliminate technical risk. Hardware wallet users are still exposed to firmware defects, supply-chain attacks, insecure backups and mistakes made when generating or storing recovery phrases. The attack also creates a difficult identification problem. Bitcoin transactions do not show whether funds were moved voluntarily or stolen using compromised keys. Investigators can group transfers based on timing and spending behavior, but wallets drained through a different method may not appear in the same cluster. Users who generated seeds on the affected firmware should therefore treat those credentials as potentially exposed even if their balances have not moved. Delaying migration could leave funds vulnerable to a later attack that does not follow the transaction pattern already identified. For Coinkite, the financial and reputational consequences will extend beyond the emergency update. Customers will expect a detailed explanation of the defect, the affected firmware range and the testing changes introduced to prevent a repeat. The company may also face pressure to explain whether it plans to compensate users whose Bitcoin was stolen.