A single hidden bug turned “air‑gapped” Bitcoin vaults into open safes and let thieves pull almost $89 million without touching a single device.
Story Snapshot
- Attackers stole about 1,367 Bitcoin, nearly $89 million, from Coldcard wallet users across three waves.
- A firmware flaw weakened seed phrases, letting hackers recreate private keys and drain funds remotely.
- Galaxy Research mapped a 41‑minute sweep of 1,196 addresses that alone took about $70 million in Bitcoin.
- Coldcard maker Coinkite now urges users to update firmware and regenerate wallet seeds or risk losing everything.
How One Wallet Flaw Turned “Safest Storage” Into A Jackpot
Coldcard hardware wallets were sold as one of the safest ways to store Bitcoin, thanks to offline key storage and “air‑gapped” design. That reputation collapsed when blockchain researchers saw funds drain from hundreds of wallets in tight bursts, all linked to a single class of devices.
Galaxy Research tracked an opening wave where 1,082.65 Bitcoin vanished from 1,196 addresses in about 41 minutes, worth roughly $70 million at the time. Those coins have stayed parked in attacker‑controlled addresses.
The break‑in did not use phishing emails or malware. Instead, hackers exploited a flaw inside the wallet’s own firmware. The bug sat in Coldcard code since around March 2021, affecting how the device generated the seed phrase—the secret words that control a wallet.
A build configuration turned off the hardware random number chip on some models. When that chip went dark, the device fell back to a software random generator that was predictable enough for an attacker to copy offline.
The Three Waves Of Theft That Emptied 4,500 Wallets
The first signs of trouble came when about 500 Coldcard users saw 594 Bitcoin, around $38 million, swept out of their wallets in less than half an hour. Lookonchain and Galaxy Research flagged the pattern and followed the coins as they moved through a few on‑chain addresses.
Once analysts realized the thefts followed the same seed‑generation flaw, they pulled back the camera.
By early August, they counted three coordinated waves of attacks targeting 4,585 addresses and draining roughly 1,367 Bitcoin, close to $89 million in value.
The first wave hit higher‑value wallets, averaging close to one full Bitcoin per victim, with 1,082.65 Bitcoin taken from 1,196 addresses. Later waves spread to thousands more wallets holding smaller balances, adding just over 200 Bitcoin in losses but widening the impact.
Researchers at Galaxy and media outlets confirm the coins came from wallets whose seeds were generated on the flawed Coldcard firmware, cementing the link between the bug and the theft. For many holders, funds had sat untouched for years, only to vanish in minutes.
What Went Wrong Inside Coldcard’s Firmware
Coinkite’s investigation and outside reports point to one core failure: bad randomness during seed creation. In normal hardware wallets, a dedicated chip creates random numbers that no one can guess, and those numbers feed into your seed phrase.
Some Coldcard Mk3 and newer firmware versions instead used a software fallback named Yasmarang when hardware random numbers were disabled.
That software generator was deterministic. Once an attacker learned how it was seeded, they could reproduce the same “random” numbers again and again.
Security teams at Block and Galaxy say this meant that seeds created on the affected devices could be brute‑forced offline. The attacker did not need to touch the hardware or trick the user. They only needed to know the firmware’s behavior and search the narrow space of possible seeds that the flawed generator produced.
That is the part that should alarm anyone who values self‑custody. When a device silently cuts randomness from 128 bits down to something much weaker, brute force goes from fantasy to real‑world crime in a long weekend.
What Coldcard Users Did Next And What This Says About Self‑Custody
Once Coinkite confirmed the flaw, the company issued security advisories telling affected users to update firmware and move funds. Owners of Mk3 and later devices with certain versions were told their seeds might be unsafe and should be regenerated on fixed firmware. The reaction across the Bitcoin community was swift.
Analysts described it as one of the largest hardware wallet failures in Bitcoin’s short history, with some calling it a wake‑up call for anyone who assumed “cold storage” was bulletproof.
I think many are still shocked and might not have a clear understanding of what happened here but let me explain.
A firmware flaw introduced in March 2021 caused Coldcard devices to skip their hardware randomness generator and fall back to predictable software-based key… https://t.co/VAWGNmRnxi
— Emmanuel Brighton (@SBE_PENXCHAIN) August 2, 2026
This episode cuts two ways. It shows why many people want control of their assets instead of trusting big intermediaries. But it also proves that self‑custody only works when the tools are honest, simple, and verifiable. A single hidden configuration mistake turned thousands of careful savers into easy targets.
For ordinary Americans looking at Bitcoin, the lesson is clear: if you are going to hold your own keys, demand real transparency, offline backup methods, and devices that treat randomness like the lifeblood of your savings, not a checkbox in a build script.
Sources:
foxbusiness.com, thehackernews.com, coindesk.com, techspot.com, cryptopolitan.com, finance.yahoo.com, kucoin.com, bingx.com














