The hardware wallet industry built its reputation on a simple promise: keep your Bitcoin offline and keep it safe. That promise took a serious hit on July 30, 2026, when attackers began exploiting a vulnerability in Coinkite’s Coldcard hardware wallets, ultimately draining what revised estimates place at 1,816 BTC, roughly $114 million, from more than 5,200 addresses. Some estimates suggest total losses could climb past $130 million as sweep activity continues. The vulnerability traces back to firmware version 4.0.1, released by Coinkite in March 2021. The flaw compromised the randomness used when generating wallet seeds, which are the master keys from which all private keys in a Bitcoin wallet are derived.
Key strength, which ideally sits at 128 bits of entropy, dropped as low as 40 bits in affected devices. At 40 bits, brute-force attacks become computationally feasible with modern hardware. By early August, Galaxy Research estimated losses at approximately 1,367 BTC across 4,585 addresses. As attackers continued sweeping vulnerable wallets in subsequent waves, that figure climbed to 1,816 BTC implicated across more than 5,200 addresses. The progression matters because it signals the exploit was not a one-time smash-and-grab but a systematic, ongoing operation targeting every wallet seeded with the flawed firmware.
Coinkite has not released a specific loss estimate. The company has indicated it is conducting a post-mortem analysis before commenting on the full scope of device compromise and user impact. The irony is that this exploit required no internet connection to succeed. The vulnerability lived in the firmware’s key generation logic.
Any wallet seeded using a compromised version of that firmware was vulnerable from the moment it was created, regardless of how carefully the owner protected the physical device afterward. Galaxy Research analysts suggest the exploit could accelerate a shift toward regulated Bitcoin investment vehicles. ETF providers rely on institutional custodians operating under regulatory oversight, with insurance frameworks and security audits that individual hardware wallet users cannot replicate. For investors currently holding Bitcoin on any hardware wallet, the immediate priority is verification. If a device was seeded using Coldcard firmware version 4.0.1, funds should be transferred to a wallet generated on a different, verified device as a precautionary measure.
Waiting for Coinkite’s official post-mortem before acting is a risk calculation that many holders may not want to make while active sweeping continues. Disclosure: This article was edited by Editorial Team.
For more information on how we create and review content, see our Editorial Policy.