Coinkite, the Toronto-based company behind the Coldcard hardware wallet, is refusing to put a number on how much Bitcoin was stolen through a critical firmware vulnerability. Independent researchers peg the damage at roughly 2,055 BTC, or about $130 million, spread across more than 7,300 compromised addresses.
The company has instead pointed journalists and victims toward third-party assessments. When your product’s entire selling point is “your keys, your coins, maximum security,” declining to quantify the fallout from a breach is a bold strategy.
What happened and how fast it unraveled
The attack began on July 30, 2026, and escalated with terrifying speed. In the initial wave, attackers drained more than 1,082 BTC in approximately 41 minutes. That is roughly $68 million worth of Bitcoin disappearing faster than most people can finish a lunch break.
Additional waves of theft continued through August 3, as attackers exploited the same vulnerability across a wider pool of affected wallets. By early August, 73 victims had contacted Galaxy Research, which has been independently tracking and evaluating the scope of the damage.
The root cause is a flaw in the random number generator used during seed phrase creation on Coldcard models Mk2 through Q. The piece of code responsible for generating the secret master key to your wallet wasn’t random enough, which allowed attackers to reconstruct private keys offline. No internet connection required. No phishing email. No social engineering. Just math and a broken RNG.
The vulnerability existed in firmware versions 4.0.1 through 4.1.9. Coinkite has since released a patch in version 4.2.0, and the company is urging all users on affected firmware to generate entirely new seed phrases and transfer their funds to freshly created wallets immediately.
The self-custody paradox
Coldcard has long positioned itself as the gold standard for Bitcoin-only hardware wallets, popular among the most security-conscious segment of the crypto community. The irony here is thick enough to cut with a knife. The very device marketed as the safest way to hold Bitcoin turned out to have a fundamental cryptographic weakness baked into its firmware for multiple versions. This isn’t a case of user error or a compromised supply chain. It’s a flaw in the core security architecture of the product itself.
Coinkite has acknowledged the issue and pledged accountability, though the company has not announced any compensation fund or insurance mechanism for affected users.
What this means for investors
The immediate concern for anyone holding a Coldcard on firmware versions 4.0.1 through 4.1.9 is straightforward: update your firmware, generate a new seed, and move your coins. Do not wait. The vulnerability allows offline key reconstruction, meaning attackers don’t need to be anywhere near your device or your network to drain your wallet.
There is also the question of market impact. When 2,055 BTC gets stolen, those coins don’t just vanish. They typically get moved through mixers, bridges, or sold on markets, creating selling pressure.
The incident is already fueling renewed debate about regulatory standards for hardware wallet security. Currently, there is no mandatory certification or audit framework that hardware wallet manufacturers must meet before shipping products. That regulatory vacuum looked tolerable when the worst-case scenario was theoretical. It looks considerably less tolerable now that 73 victims have reported losses to Galaxy Research and the total damage sits at $130 million.
The real takeaway is that self-custody is only as secure as the weakest link in the hardware and firmware stack. When the device generating those keys has a broken random number generator, “your keys” might also be someone else’s keys.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
18








English (US) ·