The Coldcard hardware wallet has been compromised — a new wave of fund withdrawals from vulnerable devices is currently being observed. According to Galaxy Research, the total stolen amount reached 1,367.05 $BTC (approximately $88.6 million) from 4,585 addresses — this is significantly higher than the initial 594.5 $BTC reported on July 30, 2026. Most of the stolen funds remain untouched in the attackers' addresses. Galaxy Research confirmed on August 2, 2026, that the draining of vulnerable addresses continues.
The Problem is Not the Firmware, but the Already Created Seed Phrases
The issue is not that the devices are malfunctioning — Coinkite updated the firmware long ago. The problem is that seed phrases generated since March 2021, due to a programmer's error, turned out to be easily guessable, and updating the firmware does not change the phrase itself. As long as the owner does not transfer the funds to a new address with a new seed phrase, the old wallet remains vulnerable — no matter how many firmware versions are installed. That is why Bitcoin continues to be withdrawn even from those who updated their devices long ago.
The reason is that when integrating the libNgU library, the devices stopped using the STM32 hardware random number generator and switched to the Yasmarang software generator, initialized with publicly accessible data — the chip's serial number and timer state. Because of this, seed phrases could be brute-forced offline, without physical access to the device.
The Coinkite developer clarified which seed phrases are at risk:
-
Mk2/Mk3 with firmware 4.0.1–4.1.9 (and up to 5.0.3)
-
Mk4/Mk5 up to version 5.6.0 (Edge — up to 6.6.0X)
-
Q up to version 1.5.0Q (Edge — up to 6.6.0QX)
Exceptions are seed phrases created using at least 50 independent dice rolls or a strong unique BIP-39 passphrase. All other owners of such devices need to generate a new seed phrase on the fixed firmware (4.2.0 and newer for Mk2/Mk3, 5.6.0 and newer for Mk4/Mk5, 1.5.0Q and newer for Q) and transfer all assets to it — until this is done, the funds remain at risk regardless of the installed firmware version.
Eight Years of Hard Work — and Minutes to Lose Everything
The story of a 39-year-old investor serves as a stark reminder of how vulnerable even the most conservative cryptocurrency storage strategies can be. The man lost 2 $BTC (approximately $130,000) in just a few minutes due to the Coldcard hack. He had bought these coins over eight years, earning them through hard physical labor, and had successfully held them even through the deepest market crashes.
The tragedy lies in the fact that the victim acted with maximum caution. He did not risk capital on hype memecoins and did not entrust his savings to centralized exchanges. For him, Bitcoin was not a speculative tool, but a lifeline. The man lived in a country under strict international sanctions amidst devastating hyperinflation of the local currency. He bought cryptocurrency as a hedge against uncontrolled money printing, to protect his family from financial collapse and retire by the age of 50.
After moving his assets to a cold wallet, he believed his years of hard work were completely safe. However, the vulnerability in Coldcard nullified everything: after the instant theft of funds, the man admitted he was completely broken and would leave cryptocurrencies forever, as his dream of early retirement was dead.
This case is particularly notable because the victims of the vulnerability were not careless speculators, but long-term holders whose "buy and hold in a cold wallet" strategy was always considered the epitome of a cautious approach. Now the crypto community hopes that the manufacturer can find a way to recover the funds and return them to users to somehow mitigate this truly sad situation.
AI Opinion
From the perspective of historical data analysis, the Coldcard case is not the first example where a weakness in a random number generator destroys trust in "cold" storage. A similar situation occurred in 2011–2015 when the browser library BitcoinJS generated insufficiently random keys; the platform DefiLlama later estimated the total losses from compromised private keys over ten years at $17 billion.
A technical aspect, obscured by the emotional side of the story: replacing the hardware STM32 generator with the software Yasmarang reduces entropy precisely where the user least expects vulnerability — inside the "closed" device without internet. This detail challenges the common notion that offline storage automatically means cryptographic reliability.








