Coldcard’s Crazy Heist of $130 Million: What Happened?

By Venga
7 min read

Table of Contents

If you’ve been in Bitcoin for a while, you’ve probably heard of Coldcard. It’s one of the most popular hardware wallets, designed to keep your Bitcoin offline and secure. Unlike hot wallets, hardware wallets store your private keys on a dedicated physical device, making them one of the safest ways to protect your crypto from hackers.

For many Bitcoin enthusiasts, Coldcard has long been considered one of the gold standards for self-custody. It’s Bitcoin-only, open source, and built with security as its main priority. Many holders specifically chose it over more mainstream wallets because of its strong reputation among the Bitcoin community.

That’s why what happened over the past week has shaken the crypto world.

So what happened?

The first signs of trouble appeared on July 30, when attackers stole more than 1,000 BTC from over 1,100 wallets in just 41 minutes. Unfortunately, that was only the beginning.

Coldcars’ website
Coldcars’ website displaying advisory message

Over the following days, more coordinated waves of attacks targeted additional wallet addresses. Unlike a typical hack that ends once the vulnerability is discovered, this one continued because attackers could still identify wallets that had been created using a vulnerable firmware from years ago. As long as those wallets remained funded, they could still become targets.

As of August 5, researchers estimate that around 2,000 BTC may have been stolen, worth up to $130 million, across around 7,300 wallet addresses. They also believe that at least 15 different attackers have been exploiting the same vulnerability, making the situation even harder to contain.

What makes this even more remarkable is the type of users affected. Coldcard is mostly used by long-term Bitcoin holders who intentionally keep their coins offline for years without making frequent transactions. Many victims had done exactly what security experts recommend, meaning buy a hardware wallet, generate their recovery phrase offline, and safely store their Bitcoin. Yet, despite following best practices, some still became victims because the weakness existed from the very moment their wallets were created.

How could this happen?

What makes this case so unusual is that the wallets weren’t hacked in the traditional sense. There was no phishing email, malware, fake website, stolen password, or compromised exchange account. The attackers never broke into the wallets themselves.

Instead, they took advantage of a flaw hidden in Coldcard’s 2021 firmware.

Let’s understand this.

When a crypto wallet is created, it generates a random and unique recovery phrase (also called a seed phrase). This recovery phrase is simply a human-readable version of your wallet’s private key, which is what ultimately gives you ownership of your Bitcoin.

Normally, this randomness is incredibly strong. There are so many possible combinations that guessing someone else’s recovery phrase is statistically impossible (with today’s computing power at least). To give you an idea, if that’s even really possible, there are 3.4 × 10³⁸ possible combinations. Written out, that’s:

340,000,000,000,000,000,000,000,000,000,000,000,000. Yes… that’s 37 zeros. 

To put that into perspective, it’s greater than the estimated number of grains of sand on Earth. Even if every computer on the planet spent billions of years trying random combinations, the chances of finding a specific wallet would still be practically zero.

But due to a software bug, some Coldcard devices didn’t always generate enough randomness.

When a specific component responsible for creating truly random numbers failed, the firmware automatically switched to a backup (or “fallback”) method. Instead of relying on the highest-quality randomness, this secondary system generated recovery phrases using predictable information, including the device’s serial number and the wallet’s creation date.

That dramatically reduced the number of possible combinations from around 3.4 × 10³⁸ to roughly 10¹² (1,000,000,000,000). That’s still an enormous number, but it’s no longer impossible to search through using modern computing power and enough time.

Think of it like hiding treasure.

Normally, it’s like hiding a single coin somewhere on an entire planet. Finding it would be practically impossible. With this bug, it’s more like hiding that same coin somewhere on one specific beach. The treasure is still hidden, but now you know exactly where to start looking.

By narrowing down the search using serial numbers and creation dates, attackers could systematically test possible recovery phrases until they eventually found wallets that contained Bitcoin. They didn’t crack Bitcoin’s encryption or bypass the wallet’s security. They simply recreated recovery phrases that should never have been predictable in the first place.

Perhaps the most surprising part is that the bug had remained unnoticed for years, despite Coldcard being open source. Normally, open-source software is considered more secure because anyone can inspect the code and report vulnerabilities. In this case, the flaw remained hidden for several years before someone finally discovered a way to exploit it.

Some experts believe artificial intelligence may have helped identify the old vulnerability by analysing large amounts of public code far more efficiently than a human reviewer could. While Coinkite itself has suggested this as a possibility, there is currently no public evidence confirming that AI played a role. Regardless of how the vulnerability was found, the incident shows how older pieces of code can still create very real risks years later.

What’s next?

Once the vulnerability was identified, Coldcard’s manufacturer, Coinkite, reacted quickly. The company publicly acknowledged the issue, explained which firmware versions were affected, and released a new firmware update that fixes the bug for anyone creating a new wallet today.

However, updating the firmware doesn’t secure wallets that were already created using the vulnerable version.

The weakness isn’t in the hardware itself, nor in the updated software. It’s in the recovery phrase that was originally generated. If that recovery phrase was created using the faulty randomness, it remains vulnerable forever, even after installing the latest update.

That’s why security experts recommend that anyone who generated a wallet using the affected firmware should create a completely new wallet with the updated software and transfer all of their Bitcoin to the new wallet as soon as possible. Simply updating the device without moving the funds isn’t enough.

This also explains why the attacks continued for several days after the vulnerability became public. Once attackers understood how to identify potentially vulnerable wallets, they could keep searching for them as long as funds remained inside.

Identified Coldcard theft events by Galaxy
Identified Coldcard theft events by Galaxy

During the latest waves of attacks, a few users managed to save their Bitcoin thanks to Bitcoin’s own transaction system. Some of the attackers initially paid relatively low transaction fees, meaning their transactions remained unconfirmed for several minutes. That small delay gave some owners enough time to notice what was happening and quickly send their Bitcoin to a new wallet while paying a higher fee, allowing their transaction to be processed first.

Unfortunately, many others weren’t as lucky. Since most hardware wallets are designed for long-term storage, many owners don’t check them every day. By the time they discovered the news, their Bitcoin had already been moved.

Researchers also believe the situation became even more chaotic after the vulnerability was made public. Rather than a single attacker, multiple independent groups appear to have started exploiting the same weakness at the same time, racing each other to find vulnerable wallets before someone else did.

A reminder for everyone

Beyond the millions of dollars stolen, this incident highlights one of crypto’s biggest questions: should you store your crypto yourself or trust a centralized platform to do it for you?

One of Bitcoin’s biggest promises has always been self-custody. If you control your own wallet, you truly own your Bitcoin. No bank can freeze your funds or block your transaction, no third party controls your money.

But with that freedom also comes responsibility.

When you manage your own wallet, you’re also responsible for protecting your recovery phrase, keeping your devices secure, avoiding scams, and making sure you’re using trusted software. There isn’t a customer support team that can reverse a transaction or recover lost funds.

That doesn’t mean self-custody is unsafe. Hardware wallets are considered one of the safest ways to store crypto for the long term. This incident is simply a reminder that no security solution is perfect.

Whether you use a hardware wallet, a software wallet, or a crypto exchange, every option comes with its own advantages and risks. The important part is understanding those risks and regularly reviewing your security to reduce them as much as possible. 

Final thoughts

This incident will likely be remembered as one of the most unusual wallet breaches the crypto industry has seen, as a tiny software bug hidden inside a wallet generation process remained unnoticed for years before eventually being exploited.

It also shows how quickly the cybersecurity landscape is evolving. As new tools, including artificial intelligence, make it easier to analyse millions of lines of code and search for hidden weaknesses and old vulnerabilities.

Self-custody is still one of the best ways to protect your assets, but security isn’t something you set up once and forget forever. It requires staying informed, keeping your software updated, and reacting quickly when vulnerabilities are discovered.

Sometimes, it only takes one tiny bug to create a very big problem.


Disclaimer: The content provided in this article is for educational and informational purposes only and should not be considered financial or investment advice. Interacting with blockchain, crypto assets, and Web3 applications involves risks, including the potential loss of funds. Venga encourages readers to conduct thorough research and understand the risks before engaging with any crypto assets or blockchain technologies. For more details, please refer to our terms of service.

Tagged in:

News

Last Update: August 07, 2026