Regulation
Coldcard Hack Total Revised Up to $130M Across a Suspected Fourth Wave
31 Aug 2026, 03:30
1 views
Admin
Galaxy Research now puts verified losses at 1,596 BTC from roughly 7,300 addresses, with a suspected additional wave pushing the running total toward 2,055 BTC.
<p>The scale of the Coldcard hardware wallet exploit has continued growing as investigators dig deeper into the incident, with Galaxy Research now verifying 1,596 BTC taken from roughly 7,300 addresses across three confirmed attack waves, and a suspected fourth wave pushing the running total toward 2,055 BTC -- worth approximately $130 million at current prices.</p>
<p>The initial wave of the attack, which began July 30, drained 1,196 bitcoin addresses in just 41 minutes, taking 1,082.65 BTC worth about $70.2 million at the time -- a striking demonstration of how quickly an attacker could exploit affected devices once the underlying vulnerability was identified and weaponized. Subsequent waves have continued adding to the total as investigators and the attacker both continue working through the pool of vulnerable addresses, the former trying to map the exploit's full scope and the latter apparently continuing to extract funds from devices that remain unpatched or unmigrated.</p>
<p>The root cause, now well-established through the ongoing investigation, traces to a firmware flaw introduced by a code change in 2021: seed generation on affected Mk3 devices quietly fell back to a weak software source of randomness, cutting effective entropy from the expected 128 bits down to as little as 40 bits -- weak enough to make private keys feasibly guessable through brute-force computation rather than requiring physical device theft or user error to compromise.</p>
<p>The growing, multi-wave nature of the exploit illustrates a particularly difficult challenge in hardware wallet security incident response: unlike a single-transaction hack with a clearly defined scope, a systemic firmware flaw affecting an unknown population of devices in the field means the true final losses may not be knowable until every potentially affected wallet has either been migrated to new keys or exploited by an attacker first -- a race that has now stretched across multiple weeks with no clear endpoint yet in sight.</p>
<p>Coinkite, Coldcard's manufacturer, has not provided updated guidance beyond its earlier advice that affected users move funds to newly generated wallets on updated firmware. With the total now approaching $130 million and still climbing, the incident stands as one of the largest hardware wallet security failures on record, underscoring the stakes of firmware-level randomness bugs that can silently undermine device security for years before detection.</p>
<p>The initial wave of the attack, which began July 30, drained 1,196 bitcoin addresses in just 41 minutes, taking 1,082.65 BTC worth about $70.2 million at the time -- a striking demonstration of how quickly an attacker could exploit affected devices once the underlying vulnerability was identified and weaponized. Subsequent waves have continued adding to the total as investigators and the attacker both continue working through the pool of vulnerable addresses, the former trying to map the exploit's full scope and the latter apparently continuing to extract funds from devices that remain unpatched or unmigrated.</p>
<p>The root cause, now well-established through the ongoing investigation, traces to a firmware flaw introduced by a code change in 2021: seed generation on affected Mk3 devices quietly fell back to a weak software source of randomness, cutting effective entropy from the expected 128 bits down to as little as 40 bits -- weak enough to make private keys feasibly guessable through brute-force computation rather than requiring physical device theft or user error to compromise.</p>
<p>The growing, multi-wave nature of the exploit illustrates a particularly difficult challenge in hardware wallet security incident response: unlike a single-transaction hack with a clearly defined scope, a systemic firmware flaw affecting an unknown population of devices in the field means the true final losses may not be knowable until every potentially affected wallet has either been migrated to new keys or exploited by an attacker first -- a race that has now stretched across multiple weeks with no clear endpoint yet in sight.</p>
<p>Coinkite, Coldcard's manufacturer, has not provided updated guidance beyond its earlier advice that affected users move funds to newly generated wallets on updated firmware. With the total now approaching $130 million and still climbing, the incident stands as one of the largest hardware wallet security failures on record, underscoring the stakes of firmware-level randomness bugs that can silently undermine device security for years before detection.</p>