Losses from a firmware flaw in Coinkite's Coldcard hardware wallet have climbed past $130 million, according to TechCrunch, yet the company that makes the device still won't put a number on it. Coinkite says it is focused on a post-mortem of the days-long attack rather than speculating on the scale of customer losses, pointing users instead to outside security research.
The root cause traces back to code introduced in 2021. Researchers at Block found that Coldcard devices could generate predictable seed phrases because of a flawed random-number generator — instead of relying on the device's hardware-based randomness, a fallback generator kicked in that produced deterministic, and therefore crackable, output. Attackers didn't need physical access to a victim's device at all; they mathematically reconstructed master keys by brute-forcing the flawed generation process, effectively reproducing a wallet's private keys from the outside.
Losses Kept Climbing
The scale of the incident grew fast. Early estimates on July 31 put the damage at close to 600 bitcoin, roughly $38 million, with reporting at the time already flagging the total as likely to rise. By August 4, outside estimates had more than tripled to over $130 million, with at least a dozen separate hackers or hacking groups independently exploiting the same bug. Coinkite published its security advisory on a Thursday and updated it again that Saturday as the picture became clearer. The incident lands inside a brutal year for crypto security broadly — the first half of 2026 alone saw more than 200 separate hacks account for upwards of $950 million in losses industry-wide.
Related: BTCPay Server Warns of Critical Flaw Under Active Exploitation
Coinkite Tells Users to Move Now
Coinkite CEO NVK put the warning to users in blunt terms:
“If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further.”
The company has pushed a firmware update and is urging every affected user to migrate to freshly generated seed phrases rather than trust anything created before the patch. Coinkite did not offer TechCrunch further comment beyond that guidance.
A Blow to the Self-Custody Pitch
The hack has struck a nerve well beyond Coldcard's own user base, since the pitch of a hardware wallet has always been that it protects even careful, technically sophisticated holders. Bitcoin commentator Guy Swann called it “the worst hit in bitcoin history to the most knowledgeable and properly secured bitcoiners.” ARK Invest's Lorenzo Valente argued the episode shows self-custody traded one set of risks for another, noting consumers have effectively swapped counterparty risk for “software risk, hardware risk, supply-chain risk, phishing risk, backup risk, and the possibility of losing everything through one mistake.” Casa CEO Nick Neuman was more direct about what that means for adoption: “You just can't ask people to roll dice to be secure with your self custody. It's a non-starter for 99% of people.”
Some industry observers now expect the fallout to push newer bitcoin investors further toward regulated custodians and spot ETFs like BlackRock's IBIT rather than toward hardware wallets — a shift that would run counter to bitcoin's founding promise of holders controlling their own keys.