The theft from Coldcard, one of the most popular Bitcoin-only hardware wallets, has grown into one of the largest self-custody failures on record. Blockchain intelligence firm Galaxy Research confirmed on August 4 that losses have surpassed $100 million — with high confidence that 1,596 BTC has been stolen from roughly 7,300 addresses across three confirmed attack waves plus 14 smaller incidents. A suspected but unconfirmed fourth wave could push the total toward 2,055 BTC, or roughly $130 million. The attack struck the exact place self-custody is supposed to be safest: coins held offline, on a dedicated hardware device, by people who followed the "be your own bank" playbook to the letter.

The number keeps climbing. This has been a moving target since it broke. Estimates rose from about $38 million when the flaw first surfaced on July 30, to $88.6 million by the weekend, past $100 million by August 4 — and some outlets, counting the suspected fourth wave, already cite figures near $114–116 million. Crucially, Galaxy stresses the exploit is ongoing, so any total is a snapshot, not a final tally.
What happened. Across several waves beginning in late July, attackers swept Bitcoin out of thousands of single-signature wallets, often in bursts of well under an hour — an initial analysis by Block, Jack Dorsey's fintech firm, traced roughly 594 BTC drained from around 500 wallets in about 25 minutes. This was not a remote hack of the devices, and not a phishing scam. The coins were taken because attackers could mathematically reconstruct the wallets' private keys.
The root cause, in plain English. A hardware wallet's entire security rests on generating your secret recovery phrase (your "seed") from true, unpredictable randomness. A firmware integration error introduced in Coldcard version 4.0.0 in March 2021 caused affected devices to skip the chip's dedicated hardware random number generator (RNG) and fall back to a predictable, software-based substitute — seeded from non-secret device details like the serial number and internal clock. That turned what should have been an astronomically large, unguessable range of possible seeds into a set small enough to brute-force offline. In short: the wallets' "random" keys weren't random enough, so they could be recreated without ever touching the device.

Who is affected — and this changed. When the flaw first surfaced, maker Coinkite indicated the risk centered on seeds generated on Mk3 devices running firmware 4.0.1 (March 2021) or later, and said newer models appeared unaffected. But as thefts continued through the weekend, Coinkite admitted that all of its models were vulnerable, and engineers have warned that essentially any Bitcoin address generated on a Coldcard could eventually be at risk. The exposure also follows the seed, not the device: users who generated a seed on a Coldcard and later migrated to a different wallet may still be at risk, because the vulnerable seed itself is the problem. Given the maker's own escalation, every Coldcard user should treat their funds as potentially exposed until they verify otherwise through official channels.
What affected users must do — now. The firmware has been patched, but updating the firmware alone does NOT fix an already-generated weak seed. If you are affected, you must generate an entirely new wallet with a fresh, secure seed and move your funds to it. Galaxy Research's guidance has been blunt: move Coldcard single-signature funds to safe locations immediately. For larger holdings, security experts recommend a multi-signature setup requiring multiple devices from different manufacturers, so a single vendor's flaw can never drain your funds alone.
Critical safety warning: an event like this draws scammers instantly. Do not follow migration "help" from social media accounts, DMs, or anyone claiming to be Coinkite or Coldcard support. Verify every instruction through Coinkite's official website only. No legitimate company will ever ask for your recovery phrase.
There is some hope of recovery. Unlike many hacks where funds vanish through mixers instantly, roughly 90% of the stolen Bitcoin reportedly remains static and traceable, much of it consolidated into addresses that haven't moved. Galaxy says it has shared around 600 suspected attacker addresses with US federal investigators, compliance firms, and cross-industry cyber investigators, and has launched a $5 million Bitcoin security fund tied to the episode. Whether victims recover anything remains uncertain, but the traceability is a meaningful difference from the typical crypto theft.
Who did it? Unknown. While recent large crypto thefts have often been attributed to state-backed groups, investigators have not yet linked this incident to any specific actor. The Coldcard exploit is one of a record number of crypto hacks in 2026 — analytics firm TRM Labs counted 207 separate incidents in the first half of the year, the most ever in a six-month period.
Why it matters beyond Coldcard. For years, the case for self-custody rested on a simple promise: hold your own keys and you remove the counterparty risk that sank exchanges like FTX. This incident is a hard reminder that self-custody replaces that risk with a different set — software bugs, hardware flaws, and user error. In a notable inversion of the post-FTX narrative, some investors reportedly moved Bitcoin back to exchanges for safety. Asset manager Grayscale framed the event as a "limited vulnerability" specific to Coldcard rather than a flaw in Bitcoin itself — noting Bitcoin's cryptography and consensus have never been breached — while pointing to spot Bitcoin ETFs with segregated custody, multi-sig, and insurance as an alternative for those who'd rather not manage keys. Competing hardware makers Ledger, Trezor, and Bitkey issued statements confirming their own devices are not affected by this flaw. Bitcoin's price showed little reaction, suggesting the market read this as a wallet-specific failure, not a systemic one.
The European/CEE angle: for the large self-custody communities across Eastern Europe — including Ukraine, where holding your own keys is often a practical necessity rather than an ideological choice — this is essential reading. The lesson isn't "move everything to an exchange." It's that self-custody demands active maintenance: know which device and firmware generated your seed, follow security advisories, and for meaningful sums, use multi-signature across different hardware brands so no single point of failure can wipe you out.
What to watch: whether the confirmed total climbs past $130M as the fourth wave is verified, whether the consolidated funds move (which could aid or complicate tracing), whether law enforcement identifies the attacker, and whether this pushes more holders toward multisig, regulated custodians, or ETFs.




