Hackers Cracked Coldcard's Math — And Drained $86 Million From Bitcoin's Safest Storage
A critical flaw in one of the cryptocurrency industry's most trusted hardware wallets has upended a foundational assumption of Bitcoin security: that keeping your coins in a cold wallet, isolated from the internet, protects them from hackers. It does not — if the device generating your keys cannot produce truly random numbers.
Key Points
- A software flaw in Coldcard hardware wallets allowed attackers to predict and reverse-engineer seed phrases generated on affected firmware
- By August 3, approximately 1,367 Bitcoin worth around $86 million had been drained from more than 4,500 wallets
- The flaw stems from a defective random number generator that used deterministic values — including device serial numbers — as fallback inputs
- Canada-based Coinkite, Coldcard's manufacturer, has released fixed firmware for all affected models
- Total crypto stolen in H1 2026 reached $972 million across 207 hacks — the highest number of incidents recorded in any six-month period, though down significantly from $2.3 billion in H1 2025
- Infrastructure and key compromises account for 15 percent of incidents but 76 percent of all losses
What Happened
Late last week, Coinkite notified users of its Coldcard devices that a security flaw in the cryptographic keys protecting their wallets had compromised some holdings. The scale of the damage grew rapidly. Reports on July 31 placed losses at approximately $38 million. By August 3, that figure had more than doubled — reaching roughly $86 million drained from more than 4,500 wallets, according to Galaxy Research.
The attack is ongoing.
Coldcard is a hardware wallet device that stores Bitcoin in so-called cold storage — offline, isolated from the internet, and considered one of the most secure methods of cryptocurrency custody available to individual users. The premise is that assets stored offline cannot be reached by remote attackers. That premise held. The attack did not breach the internet isolation. It exploited something more fundamental: the mathematics used to generate the wallet keys in the first place.
The Flaw — Broken Randomness
According to an analysis from financial technology company Block's engineering team, the core of the issue was how Coinkite implemented the random number generator used to produce seed phrases — the long string of words that serves as the master key to a wallet.
True randomness is a non-negotiable requirement of cryptographic security. A seed phrase that is genuinely random cannot be predicted or reconstructed without the original entropy that produced it. Coldcard wallets contained a fallback mechanism in their firmware that, under certain conditions, generated keys using deterministic values — including device serial numbers — rather than true random inputs.
Deterministic values are, by definition, predictable. Once researchers or attackers understood the fallback mechanism and the input values it used, they could systematically recalculate the seed phrases for affected wallets and drain the funds held within them. The internet isolation that was supposed to make cold wallets secure became irrelevant — the keys were vulnerable before they ever left the device.
"It exposes the fallacy of your crypto being offline," said Aneirin Flynn, chief executive of cybersecurity firm Failsafe. "The device is just responsible for generating your passwords, and if the underlying math is broken, then your passwords can be reverse-engineered."
The Human Dimension
For victims, the attack arrived without warning and moved at machine speed.
Jonathan Goodman, one of the affected users, said he initially assumed the flaw did not apply to him. He checked his wallet anyway. "Between 9.36 and 9.43pm on July 29th, all three of my wallets were completely drained," he said. The entire operation took seven minutes.
Goodman said the experience exposed how much blind faith he had placed in the technology. He said he would not be investing in Bitcoin or using cold wallets going forward. "If it really is this complicated and technical, perhaps it's not worth doing," he said. "Nobody knows how basically anything works."
His reaction captures something important about the broader implications of the attack. Cold wallets have been positioned as the endpoint of the security journey for individual Bitcoin holders — the final, unassailable layer of protection. The Coldcard breach demonstrates that the security guarantee of a hardware wallet is only as strong as the cryptographic implementation inside it.
Coinkite's Response
Coinkite confirmed on its website that funds controlled by seeds generated on affected firmware are at risk. Fixed firmware is now available for every affected model and release track. The company did not disclose the total number of potentially affected devices or the specific firmware versions involved in the flaw.
Users who generated seed phrases on affected firmware and have not yet moved their funds should treat those wallets as compromised regardless of whether they have yet seen any unauthorised activity. The systematic nature of the attack — in which attackers are recalculating and draining wallets methodically — means that wallets not yet targeted may still be at risk.
What the Numbers Say About Crypto Security in 2026
The Coldcard breach arrives at a moment when the broader cryptocurrency theft landscape presents a mixed picture. Total crypto stolen in the first half of 2026 reached $972 million — less than half the $2.3 billion stolen during the same period in 2025, suggesting that some defensive improvements across the industry have had an effect.
But the number of individual hacks climbed to 207 in the first half of 2026 — the highest recorded in any six-month period. More incidents, lower aggregate losses, reflects a pattern in which large single-event catastrophes are becoming rarer while smaller, more frequent attacks are proliferating.
The Coldcard breach may shift that calculus. At $86 million and climbing, it represents a significant single-event loss that illustrates the category of risk that TRM Labs' global head of policy Ari Redbord flagged in a July report. Infrastructure and key compromises represent only 15 percent of incidents but account for 76 percent of total losses. When the underlying key generation process fails, the resulting losses are categorically larger than most other attack types.
"Coldcard shows that self-custody moves the risk, it does not remove it," Redbord said.
Sources
Coinkite official notification to Coldcard users, late July 2026. Galaxy Research loss estimates, August 3, 2026. Block engineering team analysis of Coldcard random number generator flaw, 2026. Aneirin Flynn, CEO of Failsafe, statement on cold wallet security implications, 2026. TRM Labs H1 2026 crypto theft report, July 2026. Ari Redbord, TRM Labs global head of policy, statement on infrastructure and key compromise losses, 2026. Victim account from Jonathan Goodman, reported in Straits Times, August 2026.