The fallout from the Coldcard hardware wallet exploit is still unfolding. Galaxy's Head of Research, Alex Thorn, said this week that the attack draining funds from affected devices remains ongoing, and warned that Coldcard's firmware patch does not retroactively fix the underlying damage: any seed generated on the vulnerable firmware stays permanently compromised, patched device or not. Thorn's guidance was blunt: affected users need to move their funds to an entirely new wallet built from a freshly generated seed, not simply update and continue using the old one.
The root cause traces back to a single code change in Coldcard's firmware version 4.0.1, released in March 2021. A build configuration error caused some devices to fall back on a software pseudorandom number generator, seeded from public hardcoded constants, instead of the hardware-based entropy source the wallet was designed to use when generating new seeds. That flaw sat undetected for roughly five years, spanning firmware versions 4.0.1 through 4.1.9, before manufacturer Coinkite issued a fix.
A $116 Million Hit
Attackers began draining bitcoin from affected Coldcard wallets on July 30, 2026, with further waves through August 3 pushing total losses to roughly 1,816 BTC, worth about $116 million, across more than 5,200 addresses. That makes it the largest hardware wallet exploit on record and the third-largest crypto hack of the year. According to Coinkite's own security advisory, pre-fix seeds on the Mk4, Mk5 and Q models carried roughly 72 bits of entropy instead of the 128 bits the design called for, a gap small enough for attackers to brute-force given enough time and motivation.
What Affected Users Should Do
Anyone who generated a Coldcard seed between March 2021 and the July 2026 patch should treat that seed as compromised regardless of what firmware the device is currently running. Thorn's recommended process mirrors Coinkite's own guidance: generate a new seed only on updated hardware, verify the new wallet's fingerprint and a fresh receive address, and migrate funds starting with a small test transaction before moving the remaining balance.
A Reminder That Custody Has Two Failure Modes
The episode lands at an awkward moment for the self-custody argument that hardware wallet makers and bitcoin educators have made for years: keeping your own keys eliminates exchange counterparty risk, but it shifts the risk entirely onto the correctness of the device generating those keys in the first place. That tradeoff has been on display elsewhere in bitcoin markets this month too, as 28,000 BTC flowed back onto exchanges after a summer of coins moving into self-custody, a reminder that neither storage method is free of risk, just different kinds of it.
Related: Bitcoin's Summer Exchange Drain Reverses as 28,000 BTC Flow Back