A hidden flaw in one of the most trusted names in Bitcoin self-custody has triggered the largest hardware wallet breach ever recorded. The Coldcard wallet breach traces back to a firmware bug that sat undetected since March 2021, quietly weakening the device’s ability to generate truly random seed phrases until attackers found it years later and drained more than 1,778 Bitcoin from thousands of victims.
Summary
Key takeaways
- A firmware bug active since March 2021 let attackers steal more than 1,778 Bitcoin, worth roughly $112.7 million, from over 8,600 Coldcard wallet addresses.
- The flaw originated in firmware version 4.0.1, which mistakenly rerouted seed phrase generation to a predictable software-based random number generator instead of hardware randomness.
- Galaxy Research believes attackers used AI models without cybersecurity restrictions to find and exploit the bug, while US AI safety policies limited defenders from using comparable tools.
- Coinkite issued a security advisory on July 30 and shipped patched firmware by July 31, but no multisignature Coldcard wallets were affected.
- Users on vulnerable firmware must generate entirely new seed phrases and migrate funds, since old keys remain permanently compromised.
Overview of the Coldcard Firmware Breach
The Coldcard wallet breach ranks as the biggest hardware wallet compromise on record, with confirmed losses of $112.7 million spread across more than 8,600 wallet addresses. The scale alone sets it apart from previous hardware wallet incidents, since Coldcard has long marketed itself as an air-gapped, security-first device for Bitcoin holders who wanted to avoid the risks tied to software wallets.
Incident scale and timeline
The active theft phase began on July 30, 2026, and moved fast. Within just 41 minutes, attackers had already swept over 1,000 Bitcoin from more than 1,000 addresses, according to details shared by security researchers tracking the exploit. No further attacker activity has been recorded since August 6, suggesting the main wave of theft was concentrated in a short, coordinated window rather than a slow drip. The bug itself had been sitting inside Coldcard devices for roughly five years before anyone weaponized it at scale, and a developer reportedly flagged a related issue to Coinkite as early as May 2025, well before the exploit went public.
Root cause in firmware version 4.0.1
The technical root of the problem sits in a firmware update Coinkite shipped as version 4.0.1. That update accidentally rerouted seed phrase generation away from the device’s dedicated hardware random number generator and toward a software-based pseudorandom number generator instead. Software-generated randomness is far easier to predict or reverse-engineer than hardware-based entropy, which meant the private keys created under that firmware version were effectively guessable by anyone who understood the flaw. The exploit reportedly reached across multiple Coldcard models, including the Mk2, Mk3, Mk4, Q, and Mk5.
The Role of AI in the Attack and Defense
What separates this breach from a typical crypto hack is the confirmed use of artificial intelligence on both sides of the fight. Galaxy Research assessed with high confidence that at least some attackers relied on AI models without built-in cybersecurity restrictions to identify and exploit the Coldcard flaw, naming the recently released open-source Kimi K3 model as an example of the type of system likely involved.
Attackers’ AI advantage versus defenders’ restrictions
The uncomfortable twist is that the same class of tools that helped attackers was largely off-limits to the people trying to stop them. Rob Hamilton, chief executive of Anchorwatch, said safety policies at US frontier AI labs prevented security researchers from using comparable AI systems to defend against the attack in real time. That left defenders in the odd position of relying on the same Chinese open-source models the attackers had access to, just to keep pace. Hamilton and roughly 25 collaborators, including developer James O’Beirne and Calle of the Cashu project, organized under the name Bitcoin Red Team to scan code repositories across the wider ecosystem for similar weaknesses and push out patch recommendations before other projects suffer the same fate.
This asymmetry matters beyond Coldcard. If offensive AI use in cybersecurity keeps outpacing defensive access to the same tools, hardware wallet makers and exchanges could face a widening gap between how fast vulnerabilities get found by attackers and how fast they get caught by the people meant to protect users.
Response and Security Measures
Coinkite moved quickly once the exploit became visible, issuing a security advisory on July 30 and releasing patched firmware within a day, by July 31. CEO Rodolfo Novak issued a public apology over the breach. But a patch alone does not undo the damage already done to wallets created under the flawed firmware.
What Coldcard users must do now, and why multisig held firm
Any seed phrase generated while a device ran the vulnerable firmware is considered permanently compromised, even after installing the update. Coinkite and security researchers are urging users to generate a brand-new seed phrase only on the patched firmware and then move all funds into fresh wallets tied to that new seed. Skipping this step leaves funds exposed to keys that were never truly random in the first place.
One detail stands out in the damage report: not a single theft came from a multisignature wallet. Multisig setups require more than one private key to approve a transaction, so even a fully predictable single seed wasn’t enough on its own to move funds out. That distinction is likely to push more security-conscious Bitcoin holders toward multisig configurations going forward.
Of the 1,778 Bitcoin confirmed stolen, 1,531 Bitcoin remains untouched in attacker-controlled addresses, while about 246 Bitcoin has already moved, with roughly 65% routed through Coinjoin mixing transactions and the rest shifted on-chain using methods designed to obscure the trail. Galaxy Research has shared the attacker wallet addresses with exchanges, compliance firms, and law enforcement in hopes that any funds reaching centralized platforms can still be frozen. Reporting from Decrypt following Galaxy’s ongoing tracking noted that theft activity had slowed markedly by mid-August, consistent with the lack of new attacker activity since August 6, though Galaxy cautioned that the final tally of losses tied to the breach could still climb as tracing continues. For context on scale, the incident currently ranks twentieth among all recorded crypto thefts, sitting below Multichain’s $130 million loss in July 2023 and above the $100 million taken from Harmony’s Horizon bridge in June 2022.
FAQ
How did the Coldcard wallet vulnerability arise?
A firmware update in version 4.0.1 rerouted seed phrase generation from a hardware random number generator to a predictable software pseudorandom number generator, making private keys far easier to guess.
What role did AI play in the Coldcard breach?
Attackers used AI models without cybersecurity restrictions to discover and exploit the firmware flaw, while US AI safety policies prevented defenders from using similar AI tools to respond just as quickly.
What should Coldcard users do to protect their funds now?
Users must generate a completely new seed phrase on the patched firmware and move their funds to new wallets, since any seed phrase generated on vulnerable firmware remains compromised even after the update.
Are multisignature Coldcard wallets safe from this exploit?
No thefts were recorded from multisignature wallets, which require multiple keys to authorize a transaction, giving them a clear security advantage over single-key setups during this breach.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

