Coldcard Bitcoin Wallets Exploited For $88 Million

8/3/2026
3min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert at Airdrops.com
8/3/2026
3min read
Denislav Manolov's Image
by Denislav Manolov
Crypto Expert

The ongoing exploit targeting vulnerable Coldcard hardware wallets has now resulted in approximately $88.6 million in stolen Bitcoin, according to new research from Galaxy Research.

Investigators identified a third wave of coordinated thefts, during which attackers drained an additional 207.73 BTC. This pushed the total observed losses to approximately 1,367 BTC spread across 4,585 compromised wallet addresses.

Galaxy Research warned that the campaign remains active, urging anyone using single-signature Coldcard wallets generated during the affected period to move their Bitcoin immediately.

Alex Thorn, Head of Research at Galaxy, said: "The attack is ongoing-move your funds off Coldcard-generated addresses immediately if you have not done so."

Galaxy also confirmed it has shared information on around 600 suspected attacker wallet addresses with federal investigators, compliance firms, and cybersecurity organizations to help track the stolen funds.

Firmware Bug Left Wallets Vulnerable

The exploit traces back to a firmware build error released in March 2021. According to Galaxy's investigation, the software bug caused certain Coldcard hardware wallets to generate seed phrases with significantly reduced randomness, making the corresponding private keys potentially predictable.

Researchers believe the attackers are systematically identifying vulnerable wallets and sweeping funds in an automated operation.

Thorn suggested the campaign appears highly organized and programmatic, adding that it may even be orchestrated with the assistance of large language models (LLMs) to efficiently identify compromised addresses.

He warned that every single-signature Coldcard address generated using the flawed firmware could eventually be emptied, describing the thefts as a matter of when-not if.

Long-Term Bitcoin Holders Hit Hard

Many of the affected wallets belonged to long-term Bitcoin investors. Galaxy Research found that the stolen coins had remained untouched for an average of 3.18 years before suddenly being drained.

Despite the scale of the thefts, researchers noted that the stolen Bitcoin has not yet been moved from the attacker-controlled wallets, allowing investigators to continue monitoring the funds on-chain.

The incident has triggered widespread concern among Coldcard users, many of whom are now transferring Bitcoin away from affected wallets.

Security experts have advised users to exercise caution during the migration process and ensure they generate new, secure wallet addresses before transferring any assets.

Interestingly, the attacks have prompted some Bitcoin holders to temporarily move funds back to centralized exchanges such as Coinbase and Binance, reversing the industry's long-standing preference for self-custody under the principle of "Not your keys, not your coins."

Victims Share Their Stories

For some users, the warnings arrived too late. Canadian entrepreneur and coach Jonathan Goodman revealed that 18.25 BTC, valued at roughly CA$1.6 million, was stolen from his Coldcard wallets in just seven minutes on July 29.

Goodman explained that his wallet's recovery phrase had been stored offline inside a safety deposit box and had never been exposed to the internet.

Reflecting on the incident, he wrote: "Perhaps the hardest part about this is that I did everything right."

He added that he is filing reports with both local police and the Ontario Securities Commission.

The growing scale of the exploit serves as a stark reminder that hardware wallets remain dependent on secure firmware and properly generated cryptographic keys. Even devices designed for maximum offline security can become vulnerable if flaws exist in the software responsible for creating wallet seed phrases.

Share with your friends on social media:

Join the community and don't miss a crypto giveaway.

Subscribe for updates by e-mail with the latest research reviews, airdrop news, reward programs, event updates about upcoming airdrops.

By entering your email address you are accepting our Terms & Conditions and Privacy & Cookie Policy.