Coldcard wallet attack drains up to $89M in Bitcoin from 1,200+ addresses
Over four days from 30 July, 1,367 BTC worth roughly $89 million left 4,585 bitcoin addresses. No device was physically taken and no password leaked.
Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million (CoinDesk, 2026-08-01)The cause was a single Coldcard firmware release from March 2021.
Coldcard firmware routes part of seed generation through a software randomiser instead of the hardware one
First wave: 1,083 BTC out of 1,196 addresses in 41 minutes
A third wave is identified, bringing the count to 4,585 addresses and 1,367 BTC
Some holders move coins from self-custody back onto exchanges
Five years separate the moment the keys were made weak from the moment they were opened. Nothing in between would have told the owner of the device.
Retrieved 2026-08-04 · CoinDesk (tracking by Galaxy Research) · IG
A hardware wallet treats staying off the internet as its safety catch. The key never leaves the device, so the reasoning goes, there is no path for anyone to take it. That reasoning holds only if the key was made in a way nobody can guess at. A wallet's key comes from a set of words called a seed phrase, and those words are drawn by a random number generator inside the device. The March 2021 firmware on some Coldcard Mk2 and Mk3 units ran part of that step through a software randomiser rather than the dedicated hardware one. That shrinks the number of keys the device can possibly produce. An attacker never has to touch the device: generate the whole reduced set at home, then check which of those addresses holds coins. Being offline does no work at all against that.
The headline the author passed along counts 1,200 addresses. By the time Galaxy Research had counted all three waves the figure was 4,585. What matters more than the count is the way the flaw persists. Firmware can be patched, but a seed phrase already produced by that firmware stays exactly as it is. So an owner of an affected device is not made safe by updating; the coins have to move to a wallet generated fresh. That is where the five-year gap comes from.
Peter Schiff is a long-standing bitcoin sceptic who also runs a bullion dealer. It is worth reading the context in which he passed this story on. IG's write-up of the same event points somewhere else. Security researchers do not read this as evidence that self-custody is inherently riskier than leaving coins with an exchange. The two carry different categories of risk. Self-custody carries firmware defects and user error; exchange custody carries insolvency and frozen withdrawals.
So what this splits is not self-custody against exchanges. It is whether you can find out when your key was made, and by which piece of software. A key you cannot check is effectively already public, however far offline it sits.
Retrieved 2026-08-04 · Address counts and amounts are Galaxy Research's figures through the third wave, as of 2026-08-01. The dollar figure is at prices during the event and moves with the market afterwards.