The Coldcard hardware wallet vulnerability has grown from a localized 594 BTC incident into a full-blown crisis of confidence in hardware storage. Galaxy Research analysts estimate that since July 30 an attacker has drained roughly 1,816 Bitcoin, nearly $114 million, with a fourth attack wave still running. Owners of single-key Mk3 seeds bore the brunt, and the wave has already shaped investor behavior and bitcoin's price.
Four Waves in Four Days: How the Losses Piled Up
The first wave hit on July 30: in 41 minutes, the attacker drained 1,083 BTC from 1,196 addresses generated on Coldcard Mk3 devices. Funds were consolidated into a single address within minutes, making tracing harder. This is already the third revision of the loss estimate this week. It started at $38 million, then $70 million, and now the count is approaching $114 million.
Two further waves over the weekend pushed confirmed losses to 1,367 BTC across 4,585 addresses, and Galaxy Research noted that every transfer used an identical hardcoded fee with no change output, a hallmark of an automated tool rather than an owner moving their own funds.
A fourth wave began Monday and has been running for hours. Alex Thorn, head of firmwide research at Galaxy Research, said it has pushed the running total to roughly 1,816 BTC from more than 5,200 addresses. By his count, blocks 960,778 through 960,792 saw suspicious transfers at a rate of about 14 per block against a normal 0.3, roughly 45 times the usual pace.
The root cause was a 2021 firmware build error. Instead of the hardware random number generator, the code called a software fallback inherited from MicroPython. A preprocessor check only tested whether a setting was defined, not its value, so the build passed without errors even with the fallback generator wired in. As a result, seeds created on the affected firmware can be reproduced offline by anyone who works out the range of values. Manufacturer Coinkite shipped an emergency update for every model, but it does not repair seeds already generated, so affected owners still need to move funds to a fresh seed generated on the patched device.
The Fourth Wave's New Trick Complicates Things for the Attacker
Unlike the first three waves, the fourth relies on replace-by-fee. The attacker's transaction first sits unconfirmed in the mempool, and anyone who spots their address among the victims can outbid the fee and move their coins out first. Victims never had that chance before: the first two waves consolidated funds into shared collector addresses almost instantly, with transactions confirming too fast for any reaction.
Thorn deliberately published his findings based on pattern matching rather than confirmed victim reports, choosing speed over certainty. He acknowledged he had not received any direct victim reports at the time of publication.
The attack affects only single-key Coldcard seeds. Multisignature wallets remain unaffected. This time funds are moving to freshly created addresses with no history, one per victim rather than shared collector wallets. Researchers also found six destination addresses with years of prior activity, even though a freshly generated attacker address cannot have any history. That suggests some flagged addresses could turn out to be false positives. Tracing the fourth wave's funds is harder than in the first two.
Bitcoin Slipped While Exchange Inflows Hit a Record
Bitcoin's price fell below $63,000 on Monday, though other factors contributed too, including weaker risk appetite after fresh US inflation data and news around Iran talks. According to CryptoQuant, the Coldcard exploit triggered the largest spike in small exchange deposits since the FTX collapse. Owners are rushing to secure their funds or exchange Bitcoin for dollars before their address gets caught in another wave.
The reaction looked more jittery than panicked. Exchange withdrawal volumes did not fall sharply, but the share of small transactions, typical of retail holders who kept coins on Coldcard for years, rose noticeably as they scrambled to act. Analysts described the behavior as a temporary flight of capital from cold storage toward centralized venues, a natural market response to news of compromised keys rather than any real shift in the coin's supply or demand.
CZ Warns: No Wallet Offers a 100% Guarantee
Binance founder Changpeng Zhao responded to the exploit in a post on X, advising owners to spread funds across several wallets since even hardware devices with years of track record can carry hidden bugs.
"Nothing is 100%. Spread your funds across multiple wallets."
- Changpeng Zhao, founder of Binance, from a post on X, August 1, 2026
Coinkite, for its part, advises owners of affected devices to set a strong BIP-39 passphrase, use at least 99 dice rolls to generate entropy by hand, or combine both approaches. The company also launched a separate migration path for Mk3 owners, since that model is already officially out of support.
The main risks for Coldcard owners right now:
- Seeds generated on Mk3 after firmware 4.0.1 remain vulnerable even after installing the new patch.
- Updating the firmware does not restore an already created seed; a completely new one generated on the patched device is required.
- Mk4, Q and Mk5 were not directly affected, but their effective entropy is also below the intended target, roughly 72 bits instead of 128.
- Rival maker Trezor assured its users their funds are safe since it uses different seed generation code.
Coinkite Owns the Mistake as the Industry Rethinks Testing
Manufacturer Coinkite admitted the attacker most likely used artificial intelligence to review the open-source firmware code. The company had used the same method to audit its own code a few weeks before the breach, and it turned up nothing serious at the time. Coinkite added that this time the tool helped the attackers, not the defenders, since both sides work with the same models.
Block published its own independent analysis, saying none of its products, including its Bitkey wallet, were affected. Block's hardware lead urged owners of compromised devices to move funds as soon as possible. Kraken's chief security officer noted that a five-year-old flaw missed by both manual review and an earlier AI audit exposed a gap in how the industry tests firmware before release.
Confidence in hardware wallets as an unquestionably safe option took a hit this week, and asset owners are increasingly splitting funds across multiple devices and providers instead of one. The market answered with caution rather than panic. The jump in small exchange deposits and public warnings from major players show that storage security is becoming as much a wallet-choice criterion as convenience. Galaxy Research's next reports on suspicious transfers will be the key signal for whether Coinkite has managed to stop the leak of predictable seeds.




Comments
Your email address will not be published. Required fields are marked *