The $130M Coldcard Bitcoin Hack: What Happened, Are You Affected, and What to Do Right Now
"I never shared my seed phrase with anyone. My device never touched the internet. My Coldcard sat in a safety deposit box. And I still lost everything."
That's not a hypothetical. That's a real quote from Jonathan Goodman — a Canadian entrepreneur whose post was viewed 7.6 million times on X after losing 18.25 BTC worth C$1.6 million. He did everything right. The device failed him.
Here's exactly what happened in the Coldcard hack — the largest hardware wallet security failure in Bitcoin history — who is affected, and what you must do right now.
What Is Coldcard?
Coldcard is a Bitcoin-only hardware wallet made by Canadian company Coinkite. For years, it was the gold standard of self-custody. Serious Bitcoin holders, security researchers, and institutions all trusted it for one reason: it was designed so your private key never touched the internet.
It had open-source firmware, dual secure chips, and air-gapped operation. If you were storing serious Bitcoin, Coldcard was the answer.
Then July 30, 2026 happened.
The Attack: By the Numbers
Starting at around 11:00 PM UTC on July 30, 2026, an attacker began systematically draining Bitcoin from Coldcard wallets — without physically touching a single device.
Wave 1 (July 30): 594 BTC (~$38M) drained from ~500 wallets in just 25 minutes into a single address.
Waves 2–3 (July 31–Aug 1): Attack continues, more addresses swept.
Wave 4 (August 4): Another 709 wallets drained.
Final damage (as of August 11, 2026):
- $130M+ in Bitcoin stolen
- 7,300+ wallets compromised
- 15+ distinct attackers — including copycats after the original exploit went public
- 3rd largest crypto hack of 2026
The single largest sweep: 1,082 BTC drained from 1,196 wallets in just 41 minutes.
What Actually Went Wrong: The Firmware Bug
This is the part you need to understand.
Inside every Coldcard device, there are two sources of randomness used to generate your seed phrase:
1. Hardware RNG — A dedicated chip generating truly random numbers from physical processes. The secure one.
2. Software PRNG — A software substitute. Far weaker. Predictable if you know the inputs.
Firmware version 4.0.1, released in March 2021, had a build configuration error. Some devices silently fell back to the software PRNG instead of using the hardware chip — with no warning, no error message, no way for the user to know.
The result: Seed phrases were generated with far weaker randomness than designed. Effective key strength dropped from 128 bits to as little as 40 bits on older devices.
2⁴⁰ possible keys sounds like a lot. With modern computing power, it's brute-forceable in hours.
The attacker never needed to:
- Touch your device
- Know your seed phrase
- Break into your safe
- Intercept any data
They just computed the narrow range of possible keys, matched them to wallets on the blockchain, and drained whatever had funds. Automated. At scale. Across thousands of addresses simultaneously.
"I Did Everything Right" — The Brutal Truth
The most devastating part of this hack is who the victims are.
Not people who stored their seed phrase in Gmail. Not people who clicked phishing links. The victims here are the careful ones — the paranoid ones — who did exactly what every crypto security guide told them to do.
They used a premium hardware wallet. They kept it offline. They stored their seed phrase on metal plates in a fireproof safe. They never told anyone their keys.
None of it mattered, because the flaw was baked into the device they trusted — from a single line of code written five years before the attack.
As blockchain security firm TRM Labs put it: "Self-custody relocates risk rather than eliminating it."
Are You Affected?
You may be affected if:
✅ You own or owned a Coldcard hardware wallet
✅ You generated your seed phrase between March 2021 and July 2026
✅ Your firmware version at setup time was 4.0.1 or later versions from that window
You are likely NOT affected if:
- You generated your seed on a Coldcard before March 2021
- You use a different hardware wallet — Ledger, Trezor, Foundation Passport
- Your crypto is on a centralized exchange like Coinbase
The uncomfortable truth: If you set up a Coldcard anytime between March 2021 and July 2026, assume you could be affected and act immediately.
What You Must Do Right Now
Here is the critical thing most people are missing:
Updating your firmware does NOT fix your existing wallet.
The patch only prevents future seeds from being generated weakly. Your existing seed phrase is already compromised. Updating firmware on the same wallet changes nothing — the key is still brute-forceable.
The only safe action is full migration:
Step 1: Stop sending any funds to your current Coldcard wallet immediately.
Step 2: Get new hardware — either a new Coldcard with the latest patched firmware, or a different device entirely (Ledger, Trezor, Foundation Passport).
Step 3: Generate a brand new seed phrase on the new device. Write it down on paper — never digitally.
Step 4: Verify your new wallet — check the wallet fingerprint and confirm a receive address matches.
Step 5: Do a small test first — send 0.001 BTC to your new wallet, confirm it arrives, then migrate the rest.
Step 6: Consider your old Coldcard wallet permanently compromised, even if it hasn't been drained yet.
Where Is the Stolen Bitcoin Now?
Blockchain firms TRM Labs and CertiK have been tracking the stolen funds in real time.
- Most funds are pooling at a small number of attacker addresses with limited movement so far
- Some laundering has started: 64.9 BTC deposited into Wasabi (a Bitcoin mixer) and 200 ETH sent to Tornado Cash after being bridged via THORChain
- At least 15 distinct attackers identified — the original exploit group plus opportunistic copycats
- The laundering style looks amateur compared to professional state-sponsored groups like Lazarus
No specific attacker has been identified. Transaction patterns across the four attack waves suggest multiple independent actors were involved.
What This Means for Self-Custody
This hack doesn't kill the argument for self-custody. But it forces an honest conversation about what it actually protects — and what it doesn't.
Self-custody protects you from:
- Exchange hacks and insolvencies (FTX, Celsius)
- Exchange freezes and government seizure
- Counterparty risk
Self-custody does NOT protect you from:
- Firmware vulnerabilities in the device itself
- Bugs introduced years before you bought it
- Supply chain attacks
What to do going forward:
- Use multisig for large holdings. A 2-of-3 setup using independent devices means one compromise can't drain everything. Try Casa (casa.io) or Unchained Capital.
- Diversify hardware. Don't rely on one device from one manufacturer.
- Follow crypto security news. Firmware vulnerabilities don't always make headlines.
FAQs
Does Coinkite offer compensation?
No compensation program has been announced. Coinkite is providing technical guidance only.
My wallet hasn't been drained yet. Can I wait?
No. The vulnerability means your key can be computed. The attack is ongoing. Migrate now.
Is Coldcard safe to buy going forward?
New Coldcard devices with the latest firmware are safe for new seed generation. But this incident shows why diversifying across hardware manufacturers matters.
What if I use a Ledger or Trezor?
You are not affected by this specific Coldcard firmware flaw. Other wallets have their own security profiles — always keep firmware updated.
The Bottom Line
$130 million stolen. 7,300+ wallets drained. Victims who did everything right.
If you generated a seed phrase on a Coldcard between March 2021 and July 2026 — migrate your funds today. Not tomorrow. Today.
And for every crypto holder: this is the reminder that security is not a product you buy once. It's a practice you maintain.
Also read: What Happens to Your Crypto When You Die? Set Up an Inheritance Plan Now
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
👤 ABOUT THE AUTHOR
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Vishal Deshmukh is a cryptocurrency researcher,
trader, and founder of BlockHustle Crypto. With
10+ years of hands-on experience in the
cryptocurrency space, Vishal has become a
trusted voice in crypto education and market
analysis.
Vishal's journey began when he discovered
Bitcoin's transformative potential through
cryptocurrency airdrop videos on YouTube.
Since then, he has dedicated himself to
mastering every aspect of the crypto ecosystem.
EXPERTISE:
✓ Bitcoin and Ethereum market analysis
✓ Altcoin research and evaluation
✓ Cryptocurrency trading strategies
✓ Blockchain technology and DeFi
✓ Crypto security and self-custody
✓ Airdrops, staking, and passive income
✓ Whale tracking and market trends
CONNECT WITH VISHAL:
📱 Instagram: @blockhustle_crypto
🎥 YouTube: @BlockHustleus
📧 Email: blockhustle.crypto@gmail.com
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
Disclaimer: This article is for informational and educational purposes only. Always consult qualified security and financial professionals for your specific situation. For official guidance on the Coldcard exploit, visit Coinkite's official website.


