◆ Stacks
1,367 BTC
Peter Schiff (@PeterSchiff) · 2026-08-03 · original: EN

What took $89 million in bitcoin was not a break-in on the wallets

Open in the Stacks app → Read the original ↗

Coldcard wallet attack drains up to $89M in Bitcoin from 1,200+ addresses

Peter Schiff · 2026.08.03

Over four days from 30 July, 1,367 BTC worth roughly $89 million left 4,585 bitcoin addresses. No device was physically taken and no password leaked.

Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million (CoinDesk, 2026-08-01)
출처: coindesk.com

The cause was a single Coldcard firmware release from March 2021.

Five years separate the moment the keys were made weak from the moment they were opened. Nothing in between would have told the owner of the device.

Retrieved 2026-08-04 · CoinDesk (tracking by Galaxy Research) · IG

What breaks when the randomness is weak

A hardware wallet treats staying off the internet as its safety catch. The key never leaves the device, so the reasoning goes, there is no path for anyone to take it. That reasoning holds only if the key was made in a way nobody can guess at. A wallet's key comes from a set of words called a seed phrase, and those words are drawn by a random number generator inside the device. The March 2021 firmware on some Coldcard Mk2 and Mk3 units ran part of that step through a software randomiser rather than the dedicated hardware one. That shrinks the number of keys the device can possibly produce. An attacker never has to touch the device: generate the whole reduced set at home, then check which of those addresses holds coins. Being offline does no work at all against that.

Fixing the firmware does not change the seed

The headline the author passed along counts 1,200 addresses. By the time Galaxy Research had counted all three waves the figure was 4,585. What matters more than the count is the way the flaw persists. Firmware can be patched, but a seed phrase already produced by that firmware stays exactly as it is. So an owner of an affected device is not made safe by updating; the coins have to move to a wallet generated fresh. That is where the five-year gap comes from.

The question Coldcard leaves is not about self-custody

Peter Schiff is a long-standing bitcoin sceptic who also runs a bullion dealer. It is worth reading the context in which he passed this story on. IG's write-up of the same event points somewhere else. Security researchers do not read this as evidence that self-custody is inherently riskier than leaving coins with an exchange. The two carry different categories of risk. Self-custody carries firmware defects and user error; exchange custody carries insolvency and frozen withdrawals.

What the Coldcard hardware wallet hack means for self-custody (IG, 2026-08-03)
출처: ig.com

So what this splits is not self-custody against exchanges. It is whether you can find out when your key was made, and by which piece of software. A key you cannot check is effectively already public, however far offline it sits.

In three lines

Scheduled for gradingAwaiting grading

Metric
The number of bitcoin addresses drained through this defect, as counted by Galaxy Research
Now
As of 2026-08-01: 4,585 addresses, 1,367 BTC, about $89 million
Grading date
By 2026-09-30
Hit
The count rises above 4,585 by the end of September
Miss
The count does not rise above 4,585 by the end of September

Sources

  1. Original Peter Schiff (@PeterSchiff) · Coldcard wallet attack drains up to $89M from 1,200+ addresses · 2026-08-03
  2. CoinDesk 4,585 addresses and 1,367 BTC on Galaxy Research's tracking; the first wave took 1,083 BTC from 1,196 addresses in 41 minutes (2026-08-01)
  3. IG The March 2021 firmware defect on some Coldcard Mk2 and Mk3 units, and why self-custody and exchange custody carry different categories of risk (2026-08-03)
  4. Fox Business The article the original post linked to, written on the 1,200-address count (2026-08-02)

Retrieved 2026-08-04 · Address counts and amounts are Galaxy Research's figures through the third wave, as of 2026-08-01. The dollar figure is at prices during the event and moves with the market afterwards.

This author's record

3posts2directional calls2Bear
See the full record →