The whole point of a hardware wallet is that your keys never touch the internet, so nobody can steal them without physically taking the device. Over the past five days, attackers stole roughly 1,816 BTC, about $116 million, from more than 5,200 Coldcard addresses without touching a single device. They did not need to. A firmware bug from 2021 meant the "random" numbers behind thousands of seed phrases were not random enough, and someone finally did the math.

The thefts began on July 30 with a wave that Galaxy Research clocked at 41 minutes: about 1,083 BTC, worth $70 million, swept from 1,196 addresses in one automated run, per The Hacker News. A second wave followed on July 31, a third over the weekend, and a fourth on Monday morning, bringing the total to $116 million by Fortune's August 3 count. The attack was still unfolding as Coinkite, the Canadian company behind Coldcard, published an open letter telling affected users to move their coins immediately. Its founders called the stretch, in their words, "some of the hardest in this company's history."

A dice roll that was never rolled

The vulnerability traces back to a March 2021 firmware build for the Coldcard Mk3, versions 4.0.1 through 4.1.9 and some earlier releases, per BleepingComputer. When those devices generated a new wallet, a bug routed the process through a software random number generator instead of the dedicated hardware chip that was supposed to supply the entropy. The output looked like a normal 12 or 24 word seed phrase, and behaved like one, right up until someone realized the pool of possible seeds was small enough to search. That is the quiet horror of the flaw: the keys were weak from the day they were created, and the weakness sat dormant for five years.

Whoever ran the sweep had done the homework. Every theft transaction used an identical hardcoded fee of 30 satoshis per virtual byte and left no change output, the signature of an automated tool, and Chainalysis found the attacker prioritized the richest wallets first, taking about $30 million in the first ten minutes and $1.8 million from a single victim. Coinkite disclosed the flaw publicly about 30 hours after the first wave, shipped patched firmware by August 1, and per Benzinga halted shipments of affected stock. None of that returns a coin.

Cumulative BTC drained in the Coldcard exploit
0 BTC 600 BTC 1,200 BTC 1,800 BTC Jul 30 Aug 1 Aug 3 Jul 30: 1,083BTC Aug 1: 1,367BTC Aug 3: 1,816BTC 1,816BTC 41-minute first wave
Figure 01Reported cumulative totals: July 30 first wave per The Hacker News, August 1 three-wave count per Galaxy Research, August 3 four-wave total per Fortune.

If you own a Coldcard, this is the checklist

The exposure question comes down to where your seed was born. A seed generated on a Mk3 running the 2021 firmware is the danger case, and Coinkite's guidance is blunt: assume it is compromised and move everything to a fresh seed on patched firmware or a different device. Users who supplied their own entropy with dice rolls, and users who locked their wallet behind a strong BIP-39 passphrase, have real protection, because the passphrase is not stored anywhere the flawed generator touched. But the company is urging migration even for edge cases, and we think that is right. When the cost of being wrong is everything, you do not litigate probabilities, you move.

Figure 02The migration logic for Coldcard owners, per Coinkite's advisory. When in doubt, treat the seed as burned.

The second, uglier phase of every incident like this is the scavenger wave. Expect fake Coldcard checker sites, fake refund portals, and urgent messages offering to help victims migrate, all engineered to harvest the seed phrases the original attacker could not reach. The rule we repeat in our scam guide applies word for word: anyone who asks for your seed phrase is stealing from you, whatever the letterhead says.

What it breaks, and what it does not

There is a tempting wrong lesson here, and CoinDesk captured the debate within a day of the first wave: if cold storage can be drained, why not just hold the ETF? Our answer is that the exploit is an argument against unaudited entropy, not against self-custody. The flaw was not in bitcoin, not in the secure element, not in the seed phrase standard; it was one firmware bug in one product line five years ago, exactly the class of risk that diversifying across devices, adding a passphrase, and following the basics in our wallet security guide is built to contain. The market seems to agree on the systemic read: bitcoin traded near $62,500 through the weekend, closer to its ETF flow worries than to the hack, and the coins themselves moved with no protocol failure at all. The trust that broke this week was narrower and more personal: the box you bought so you would never have to think about this again turned out to be the one thing you needed to think about.