COLDCARD hardware wallet flaw
web3isgoinggreat-incident-entry
https://www.web3isgoinggreat.com/single/coldcard-hardware-wallet-flaw
Latest reviewed change
source content difference between and
The entry raised its loss figure from more than 1,367 BTC (about $89 million) to more than 2,000 BTC (about $130 million), restated the body as at least 2,055 BTC (about $130 million), added Galaxy Research's estimate of 15 unique attacker groups, and added a link to the Galaxy Research tweet thread.
Threads
Go to full timeline
July 31, 2026
-Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets
+Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets
Coldcard logo (attribution)
-Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets.
-An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging.
First lines only. The complete diff is in the timeline below.
- Organisation
- Web3 is Going Just Great
- Evidence role
- Reporting
- Published
- not established
- Source changes
- 1
- Detected differences
- 1
- Unreviewed
- 0
- Copies held
- 2
A stable incident-database entry with independent framing and outbound archive links. Held as a compact secondary chronology and discovery aid, not as a substitute for the primary publications it cites. Its summary and loss figure are the publisher's own.
Every check is recorded, including checks that found no text change. A detected edit is therefore bounded between two checks. The publisher's exact save time is not observable from this record. Last checked .
This post is held twice: here, with this project's own note on why it matters, and again as part of the conversation captured at , which is polled for changes. Both copies are the same post; neither is a separate event.
Snapshot and diff bodies for this chain monitor are held in the local evidence archive but withheld from the public site because they can contain the addresses of people who published nothing themselves. Capture times and reviewed change summaries remain available below.
Held captures
-
The entry raised its loss figure from more than 1,367 BTC (about $89 million) to more than 2,000 BTC (about $130 million), restated the body as at least 2,055 BTC (about $130 million), added Galaxy Research's estimate of 15 unique attacker groups, and added a link to the Galaxy Research tweet thread.
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 7 lines
Threads Go to full timeline July 31, 2026 -Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets +Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets Coldcard logo (attribution) -Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets. -An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging. +Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered at least 2,055 BTC (~$130 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets. +An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research. Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built". "Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets", Decrypt [archive] "Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep", CoinDesk [archive] +Tweet thread by Galaxy Research Theme tags: Hack or scam Blockchain tags: Blockchain: Bitcoin Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page.Extracted text as captured
HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagramThreadsRSSLeaderboardGlossaryContributeNewsletterStore Web3 is Going Just Great ...and is definitely not an enormous grift that's pouring lighter fluid on our already smoldering planet. Created by Molly White. Subscribe to her newsletter for weekly recaps. Twitter Mastodon Bluesky Instagram Threads Go to full timeline July 31, 2026 Coldcard hardware wallet flaw sees more than 2,000 BTC (~$130 million) drained across thousands of wallets Coldcard logo (attribution) Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered at least 2,055 BTC (~$130 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets. An estimated 2,055 BTC (~$130 million) and counting has been drained in the days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Attacks have come from an estimated 15 unique groups, according to Galaxy Research. Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built". "Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets", Decrypt [archive] "Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep", CoinDesk [archive] Tweet thread by Galaxy Research Theme tags: Hack or scam Blockchain tags: Blockchain: Bitcoin Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page. Source code | ContributeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
-
Recovered from the Internet Archive rather than captured by this project. The row records that third-party provenance separately from captures made by this project.
What changed from the previous capture 0 lines
Extracted text as captured
HomeAboutWhat is web3?FAQLicenseTwitterMastodonBlueskyInstagramThreadsRSSLeaderboardGlossaryContributeNewsletterStore Web3 is Going Just Great ...and is definitely not an enormous grift that's pouring lighter fluid on our already smoldering planet. Created by Molly White. Subscribe to her newsletter for weekly recaps. Twitter Mastodon Bluesky Instagram Threads Go to full timeline July 31, 2026 Coldcard hardware wallet flaw sees more than 1,367 BTC (~$89 million) drained across thousands of wallets Coldcard logo (attribution) Thousands of users of a hardware wallet called Coldcard, a physical device developed by the Canadian Coinkite firm to allow bitcoin holders to store their bitcoin on a device that's not connected to the internet, have suffered more than 1,367 BTC (~$89 million) in combined losses after thieves began exploiting a flaw with the wallet firmware's seed phrase generation. A 2021 version of the device firmware, which affects a wide range of Coldcard devices, skipped the device's more secure hardware randomness generator and instead fell back to generating seed phrases with random numbers seeded from the device's serial number and clock registers. The resulting seed phrases are relatively trivially guessed, and hackers have been methodically draining vulnerable wallets as researchers warn that all vulnerable Coldcard devices will be drained soon if their owners do not move assets to secure wallets. An estimated 1,367 BTC (~$89 million) and counting has been drained in the two days following the discovery of the attack, which began with an attack that saw 594 BTC ($38 million) drained from about 500 separate wallets. The first attack seemed to intentionally target higher-value wallets, with only wallets containing 0.15 BTC (~$9,500) or more impacted. Subsequent attacks have seen funds moved to around 600 attacker wallets, according to Galaxy Research, although the number of unique attackers is not clear at this point, and attackers regularly use multiple wallets to make tracing stolen funds more challenging. Hardware wallets are often used by more security conscious users, or those with more significant sums of money at risk, because the lack of internet connection makes the devices less vulnerable to phishing or malware-based attacks. However, if a wallet seed phrase can be obtained by an attacker, the lack of internet connection is no barrier to theft. Coldcard describes itself as "ultra-secure", and its website is filled with reviews describing the product as "one of the most secure Bitcoin hardware wallets ever built". "Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets", Decrypt [archive] "Major bitcoin wallet flaw drains $38 million worth of BTC in 25-minute sweep", CoinDesk [archive] Theme tags: Hack or scam Blockchain tags: Blockchain: Bitcoin Text is licensed under a Creative Commons Attribution 3.0 Unported License. All attribution can be found on the attribution page. Source code | ContributeExcerpt only. The complete copy is held offline and backs quotations on this site. The original publication remains the canonical public source.
0 presentation-noise differences. Sidebar, ticker and other page chrome churn that our review classified as not being changes to what the source says.
The excerpts and plain unified diffs above show the text this project held and how it changed. To verify a quotation, compare it against the page itself or against the Internet Archive's copies, which are independent of this project.
Complete captures are held offline rather than mirrored here, so this page shows diffs and excerpts. If a quotation is ever disputed, the full copy can be produced. Ask.
Compare the screenshot or a quotation against the original while it is available.