BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
BTC/USD $68,420 +2.8%
ETH/USD $3,540 +1.4%
SOL/USD $142.80 -0.6%
BNB/USD $605.20 +0.9%
XRP/USD $0.62 -1.2%
DOGE/USD $0.18 +5.4%
Policy

Your Coldcard Firmware Update Will Not Save the Wallet You Already Have

On July 30, bitcoin started leaving wallets that nobody had touched. Inside twenty-five minutes, roughly 594 BTC drained out of about 500 separate wallets and landed in a single consolidation

AnonymousCryptoCompass newsroom
August 7, 2026
6 min read
NEWS
Your Coldcard Firmware Update Will Not Save the Wallet You Already Have
CryptoCompass editorial visual for policy coverage.

On July 30, bitcoin started leaving wallets that nobody had touched. Inside twenty-five minutes, roughly 594 BTC drained out of about 500 separate wallets and landed in a single consolidation address.

Nothing was phished. No device was stolen. The cause traces back to a firmware release from March 2021.

A build configuration error in Coldcard firmware version 4.0.1 caused some devices to generate wallet seeds using a weak software random number generator instead of the hardware entropy source they were designed to use. Effective key strength collapsed from a designed 128 bits to as little as 40 bits on older units.

Forty bits is brute forceable with ordinary modern computing. That is the whole attack. An attacker never needs to see, hold, or connect to the physical device.

Four waves, and the count is still moving

TRM Labs published its assessment on August 5 and put the running tally at roughly 1,816 BTC, worth close to $116 million, drained from more than 5,200 addresses across four waves. A fourth wave was still moving through the mempool when that assessment was written.

Galaxy Research, whose tally TRM cites, has been reported at a higher figure elsewhere. Coverage on August 4 put Galaxy's estimate at about 2,055 BTC and $130 million across more than 7,700 addresses. TechCrunch and Elliptic both landed near the $130 million mark that same day.

Both numbers are live estimates from the same investigation window, not competing final audits. Anyone quoting a single figure as settled is getting ahead of the evidence.

Source

Date

BTC lost

USD estimate

Addresses affected

TRM Labs assessment

August 5, 2026

~1,816 BTC

~$116 million

5,200+

Galaxy Research, as reported

August 4, 2026

~2,055 BTC

~$130 million

7,700+

Elliptic, via TechCrunch

August 4, 2026

not stated

~$130 million

not stated

One detail sharpens over time rather than blurring. Galaxy's Alex Thorn said on August 4 that the firm now estimates at least 15 separate attackers are working the same vulnerability, up from the small number of operators behind the first three waves.

Once a flaw is public and well understood, imitators arrive. That lengthens the danger window for anyone who has not moved yet.

Why a firmware update does not close the door

This is the part most readers get wrong, and it matters more than the loss total. Updating firmware fixes seed generation going forward. It does nothing to a seed that was already generated under the broken build.

If your recovery seed was created on an affected Coldcard between March 2021 and the recent patch, that seed is already weak in the mathematical sense. Coinkite has shipped emergency firmware for all affected models and destroyed its remaining vulnerable inventory.

Neither action reaches backward into a key that already exists. The migration path is unglamorous and non-negotiable.

Generate a brand new seed on patched hardware. Verify the new wallet fingerprint and a receive address. Send one small test transaction, confirm it lands, then move the rest.

Hardware wallets have been broken in a lab before without anybody losing money, and the industry has treated those findings as academic. A cybersecurity firm publicly demonstrated an attack on a popular hardware wallet in an earlier case that never produced mass theft.

This one is different because the weakness sits in the key itself rather than in the device that holds it.

The laundering pattern says something useful

TRM's tracing shows most victim funds sitting at a small number of attacker-controlled addresses with almost no onward movement. So far the laundering amounts to one 64.9 BTC Wasabi deposit and 200 ETH sent to Tornado Cash on August 4.

That is exploratory behavior. Professional crews move faster, and TRM specifically contrasts this pattern against North Korea's TraderTraitor, which typically begins aggressive laundering within hours.

Optimisus has covered how quickly that machinery works when state-linked attackers took $577 million from DeFi in eighteen days. TRM is not attributing the Coldcard theft to any specific actor at this stage.

Slow laundering is the one piece of good news here. Coins that have not moved are coins that can still be traced, flagged at exchanges, and occasionally recovered.

Analytics firms have helped claw back stolen bitcoin before when the funds stayed visible long enough. Galaxy says it is passing attacker and victim addresses to US federal law enforcement, exchanges, and compliance firms.

What this actually changes about self-custody

Self-custody moves risk. It does not delete it. The industry has spent years arguing that holding your own keys removes counterparty risk, which is true, while quietly skipping the part where it adds implementation risk instead.

A wallet is only as trustworthy as the process that generated its key. Open source code and third-party audits raise the floor, and Coldcard has both. Neither caught a build configuration error that sat in shipped firmware for five years.

The practical takeaway is defense in depth rather than device loyalty. Multisignature setups that combine independently designed devices with independently generated entropy reduce dependence on any single implementation.

Individual holders have lost life-changing sums to single-device failures before, including a North Carolina resident who lost $3 million in XRP after his hardware wallet was compromised.

The pattern repeats because the mitigation is inconvenient and the risk feels abstract right up until it is not.

What to watch next

Three things will decide how this story reads in a month. Whether the loss tally stabilizes near $116 million or keeps climbing as unmigrated wallets get picked off.

Whether the attackers find a laundering route for a sum this large or leave it sitting traceable. And whether Coinkite faces legal exposure for a defect that shipped in 2021 and was found by attackers rather than by an audit.

Until then, the guidance has not changed and it is not complicated. If you generated a Coldcard seed between March 2021 and the patch, treat that seed as compromised and move the funds today.

Sources

This is not financial advice.

Optimisus covers crypto and technology news for readers who want the detail behind the headline.