NEW YORK (TechGenez) – Hackers have stolen more than $100 million worth of Bitcoin from users of Coldcard hardware wallets in what is now one of the largest crypto thefts in recent years.
The attack targeted a vulnerability in Coinkite’s Coldcard firmware that allowed attackers to guess users’ seed phrases without ever touching the physical device.
As of Monday, blockchain intelligence firm Galaxy Research had identified 1,596 Bitcoin stolen from roughly 7,300 addresses. If a suspected fourth wave of attacks is confirmed, the total could rise to 2,055 Bitcoin (worth around $130 million at current prices).
How the Hack Worked
The flaw dated back to March 2021. A coding error meant the Coldcard wallets (Mk3, Mk4, Mk5 and Q models) generated seed phrases using a predictable software fallback instead of the device’s dedicated hardware random number generator.
CoinKite’s Coldcard wallet was hit by a massive exploit draining over 1,500 BTC ($100M+) due to a silent 2021 firmware RNG bug. Will Owens baited an automated drainer bot and won an RBF fee race live onchain. And open-source AI models are officially rewriting the playbook for… pic.twitter.com/GNC87NvwwK
— Galaxy Research (@glxyresearch) August 4, 2026
Hackers simply regenerated the same seeds offline and scanned for addresses that held Bitcoin. The process was so efficient that one major wave drained 1,082 Bitcoin in just 41 minutes.
Coinkite has since released emergency firmware updates and destroyed remaining vulnerable inventory. However, the updates do not repair seeds that were already created on the old firmware — so affected users must manually move their funds.
Who Is Affected and What to Do
Anyone who generated a seed phrase on a Coldcard wallet using firmware versions from March 2021 onward is at risk. This includes both current users and those who purchased the device years ago.
Coinkite has urged all owners to update their devices immediately and generate a new seed phrase. Galaxy Research has confirmed more than 73 victims so far, and the firm estimates that 90% of the stolen Bitcoin has not yet been moved.
Experts say many users may still be unaware of their exposure, which is why the company has been contacting as many addresses as possible.
Broader Impact
The hack has renewed concerns about the security of hardware wallets, which are designed to keep private keys offline. Many users rely on these devices for long-term storage, believing they are the safest way to hold Bitcoin.
The incident also highlights a recurring problem in the crypto industry: even “air-gapped” devices can be vulnerable if their firmware contains predictable randomness.
Coinkite has stated that the threat is still active. The company continues to monitor the situation and has destroyed vulnerable stock. Law enforcement agencies worldwide are investigating the attack, but the identity of the hackers remains unknown. Galaxy Research suspects at least 15 separate operators have taken part.
Conclusion
The Coldcard hack serves as a stark reminder that no security system is perfect. Even the most trusted hardware wallets can be compromised through firmware flaws, and users must remain vigilant. As the crypto industry grows, protecting private keys has never been more important.

