Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Losses Top $115M In Coldcard Bitcoin Hack: Galaxy Research

17 August 2026 at 17:32

Bitcoin Magazine

Losses Top $115M In Coldcard Bitcoin Hack: Galaxy Research

New data from Galaxy Research shows that $115 million in bitcoin has been lost in the Coldcard theft. 

Writing on X Sunday, Galaxy Research said that it had spoken with over 200 victims to support them and gather intelligence on the attackers. 

The figures are based on the price of bitcoin at the time of the attack. 

Coldcard losses have exceeded $115M (based on the price when coins were stolen)

Galaxy Research has spoken with 200+ victims to support them and gather intelligence on the attackers

This thread contains additional charts and info 👇 pic.twitter.com/H2K141mugF

— Galaxy Research (@glxyresearch) August 16, 2026

Hackers started taking bitcoin stored using Coinkite’s popular Coldcard hardware wallet on July 31. 

Canadian company Coinkite said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases. 

The number has slowly risen as the criminals have targeted more recent devices while Coinkite and other Bitcoiners have urged Coldcard users to immediately move their funds. 

Galaxy Research last week said that it estimates at least 15 separate attackers were exploiting the bug independently. 

Previous research from Galaxy found that the typical stolen coin had sat untouched for 3.5 years, and a striking 88% of pilfered funds were at least a year old. 

The firm is still confirming how much is stolen, and has said that total losses could exceed $130 million. 

Since the attack, cautious investors have been moving their coins to other storage solutions — including exchanges.

Coinkite said in a statement this week that the bug in its software “silently went unnoticed” and “its potential impact grew with every release” of its products. 

Days after the first hack, the company urged investors to update their software or move their funds off the popular hardware wallet. 

This post Losses Top $115M In Coldcard Bitcoin Hack: Galaxy Research first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Coldcard Bitcoin Hack: Victims Report Median Loss of 1 BTC as Theft Tops $111 Million

7 August 2026 at 14:02

Bitcoin Magazine

Coldcard Bitcoin Hack: Victims Report Median Loss of 1 BTC as Theft Tops $111 Million

New analysis of Bitcoin theft reports reveals that stolen funds overwhelmingly came from long-dormant wallets, with victims reporting a median loss of over one coin.

Data posted on X from Galaxy Research’s Alex Thorn looked at 250 victim reports and found the typical stolen coin had sat untouched for 3.5 years, and a striking 88% of pilfered funds were at least a year old. 

By address, losses ranged from a median of 0.014 Bitcoin to a mean of 0.212 Bitcoin, while individual victims reported a median loss of 1.022 Bitcoin and an average of 4.04 Bitcoin — with one unlucky holder losing as much as 58.97 coins. 

Hackers started by taking over $35 million in Bitcoin from wallets last week Thursday. Coinkite, which makes Coldcard, said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases. 

The theft continued throughout the weekend while Coinkite and other Bitcoiners urged Coldcard users to immediately move their funds.

Galaxy Research said Friday that a total of $111 million has been confirmed stolen but the number could be much higher as it continues its research. 

“We have many more coins we are vetting for confirmation — we think total losses likely exceed $130 million,” the firm wrote on X. 

Since the attack, cautious investors have been moving their coins to other storage solutions — including exchanges.

Coinkite said in a statement this week that the bug in its software “silently went unnoticed” and “its potential impact grew with every release” of its products. 

Days after the first hack, the company urged investors to update their software or move their funds off the popular hardware wallet. 

This post Coldcard Bitcoin Hack: Victims Report Median Loss of 1 BTC as Theft Tops $111 Million first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Self Custody Is Dead. Long Live Self Custody

By: Juan Galt
4 August 2026 at 17:25

Bitcoin Magazine

Self Custody Is Dead. Long Live Self Custody

The Coldcard hack last week dealt a low blow to certain elements of the Bitcoin industry. A somber introspection has begun to question many of the practices and assumptions involved in securing bitcoin at a retail level. The consequences of this process might not be visible for many months. 

Some are saying that self-custody is dead. Some reports estimate that over 11,000 bitcoins were moved to custodial exchanges last week as users fled one of the most popular hardware wallets in the Bitcoin industry. The hack, which is ongoing and users can still save themselves from, has seen north of 1,300 bitcoins stolen, with some estimates as high as 2,000 coins. 

Coinkite in particular and its most vocal founder, NVK, had very strong opinions about what it took to secure bitcoin private keys from hackers. Its hardware wallets were airgapped to make sure malware could not exfiltrate data through USB cables. It used low-resolution, LED screens to avoid the complexity of touch screens. It developed protocols like BBQR and integrated NFC so that information could be transferred between the device and a computer without them touching or sharing SD cards. The list of paranoid design choices that made Coldcards iconic is long.

Yet the hackers involved in the theft of bitcoins held in Coldcards last week did not use any methods you might see in a modern spy movie. They exploited the one feature Coldcard should have had absolutely locked down. The generation of keys with high enough randomness, also known as entropy. In other words, secrets securing that are actually, mathematically hard to guess. While the devices were intended to use high-quality sources of entropy, the firmware had a bug which did not, resulting in Bitcoin private keys that were, in turn, easy to guess. The bug went undiscovered for years, and the product only grew in popularity in the meantime, until last week.

“Just buy the ETF bro”

Despite this loss, which wounded a cohort of Bitcoiners who were among the most committed. Bitcoin can not give up on self-custody and expect to retain its integrity. At least that is what many in the industry believe, and the case for that is clear.

Satoshi Nakamoto’s white paper clearly intended Bitcoin to be a solution to trusted third parties and intermediaries. It eloquently made the case against trusted hierarchies of finance, as the 2008 financial crisis revealed the deep systemic risks and flaws legacy finance has led to. Many believe the 2008 crisis was never escaped, its consequences haunting us to this day. 

This may be unpopular, but we never escaped the 2008 financial crisis. We just shifted the pain.

— Nayib Bukele (@nayibbukele) July 29, 2026

Going further back to the birth and proliferation of the modern banking system and its fiat currency. The 6102 executive order signed by President Franklin D. Roosevelt in 1933 saw the persecution and confiscation of gold from centralized trusted third parties and citizens alike. $300,000,000 in gold was returned after the executive order threatened gold owners with heavy fines and jail time if they did not sell their bullion to the banks at $20,67 per ounce. Over 14 million troy ounces worth of gold were turned in as a result. Another 200 million troy ounces are estimated to have been held in the American banking system at the time. The banking system, not just in the U.S. but worldwide at the time, was built atop the gold standard.

The U.S. was the largest economy of the world at the time, with the biggest concentration of gold inside its borders. Its abandonment of the gold standard was a death blow to gold as a free market pricing mechanism for goods and services as a whole. Governments throughout the world, now free from the chains of sound money, quickly fed and fattened from the hidden tax of inflation. At the time of the EO, the price of gold was artificially fixed to $20.67 an ounce; not a year later, it was repriced to $35 with the passing of the Gold Reserve Act in 1934, a 69% devaluation in the dollar. 

The fiat standard was thus delivered to governments throughout the world on a silver platter, by an unholy alliance between the banking system and politicians. It granted central banks the legal right to counterfeit money, to print it at will. It was soon followed by World War Two, which was of course funded by fiat currency. Tens of millions of people sacrificed in this war at the altar of state power. 

Fast forward a hundred years and U.S. government debt demands almost a trillion per year be paid in interest alone, with total owed close to 40 trillion and debt to GDP at 123%. These are arguably the inevitable yet predictable consequences of the death of the gold standard. The purchasing power of the dollar has collapsed in the century that followed, at the same time as technology has gone parabolic in its efficiency gains. That is only possible with money that has continually become worthless for decades. And the dollar is the best of the fiat lot.

Confiscation of gold in a rising power like the United States murdered the gold standard. It, however, could not have been possible if civilian custody of gold had been wider and more distributed. Many of the civilians who returned millions in gold after the 6102 EO had just taken it out of their accounts in a bank run. Their names were known, the amount of gold they held, tallied.

If gold was easier to move in large quantities. If private gold ownership totals had been more ambiguous. If removing the free flow of gold had not been so easy for the state to do, by knocking on the doors of bankers and pointing a gun, then perhaps the economies of the world would not have been able to withstand such a vast and destructive war, as was WWII for so long, in the following decade. 

Bitcoin is Gold, Engineered To Survive a 6102 EO

Bitcoin poses an alternative to gold, designed to learn from its inadequacies. Bitcoin has better properties to resist and survive such a confiscation. Bitcoiners envision and aspire to unlock a world that adopts Bitcoin as a global monetary standard. Where a large minority or even a small majority of the global economy uses Bitcoin as their primary store of value. In such a future, Bitcoin would take the place of gold and return sound money to the so-called capitalist order.  

To reach global reserve currency and defend this position, Bitcoin will need to be better than gold, and it can be better precisely because of its digital nature. The control of private keys, as difficult as it seems now in the shadow of the Coldcard hack, nevertheless can be far more powerful than any physical vault. Multi-signature scripts alone unlock distributed storage of Bitcoin private keys, such that a threshold of them must approve to move coins. This means that multi-jurisdictional, multinational vaults can exist and escape or resist the greedy hands of a large state that might attempt a new kind of 6102 takeover. 

The digital nature of Bitcoin means large amounts of value can be moved easily as well, without having to send the navy on a mission to pick up the gold. Without having to build a trusted hierarchy of banking custodians to transfer it. Civilians, with tools available today and better tools that are yet to come, might be able to hide their Bitcoin ownership as has been done in war-torn countries like Ukraine already, escaping a fearsome state’s grip over the public’s wealth.

Ultimately, a major hardware wallet manufacturer has failed the Bitcoin industry. The fundamental qualities of money remain the same, and among them all, as identified by Aristotle and others beyond him, Bitcoin remains king. 

“Bitcoin vs gold vs fiat One is not like the others” – @BITCOINARCHIVE 

This post Self Custody Is Dead. Long Live Self Custody first appeared on Bitcoin Magazine and is written by Juan Galt.

Coldcard Bitcoin Theft Continues, Now Estimated Over $114 Million In Total Stolen

3 August 2026 at 10:05

Bitcoin Magazine

Coldcard Bitcoin Theft Continues, Now Estimated Over $114 Million In Total Stolen

Hackers continue to drain Coldcard Bitcoin wallets, with the total amount stolen now estimated to be standing at over $114 million. 

A fourth wave of attacks likely started on Sunday evening, according to Galaxy Research’s Alex Thorn. Posting at around 7:50pm in New York, he revealed then that 388.9 Bitcoins worth over $29 million had been moved in new transactions that were highly likely to be part of the theft. 

Hackers started by taking over $35 million in Bitcoin from wallets on Thursday. Coinkite, which makes Coldcard, said that a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases. 

The theft continued throughout the weekend while Coinkite and other Bitcoiners urged Coldcard users to immediately move their funds.

Posting on X on Monday, Trezor’s Josef Tětek wrote that the biggest transaction in the ongoing theft so far was 51 Bitcoins. 

The biggest drained address (so far) is 51 BTC. Damn. Imagine owning 50+ btc in cold storage and losing it all. Must be absolutely crushing. pic.twitter.com/qu6CiQOjeV

— Josef Tětek (@JosefTetek) August 3, 2026

Coinkite has since admitted all of its models were vulnerable following more thefts. Engineers have warned that all Bitcoin addresses related to Coldcard could be at risk eventually. 

The company said Sunday that it was asking “hard questions about our company.”

“The last three days have been some of the hardest in this company’s history, and for a lot of the people reading this, they’ve been something much worse,” Coinkite said. 

“Money that took years to save, gone. Trust that took years to build, broken. That impact is real, and for some, the damage is permanent.”

The company added that it had destroyed its remaining Coldcard inventory manufactured with the vulnerable firmware, and shipments of the product have been halted. 

Coinkite makes a number of Bitcoin products, including the popular cold storage hardware wallets.

Engineers at payments company Block investigated the hack and reported that the hackers used a top blockchain services provider for help in moving the funds, and that they’ve contacted the provider and federal authorities with their findings. 

This post Coldcard Bitcoin Theft Continues, Now Estimated Over $114 Million In Total Stolen first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach

By: Juan Galt
31 July 2026 at 13:57

Bitcoin Magazine

Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach

Over a thousand bitcoins are believed to have been stolen so far in a hack that started to be discussed on social media in the afternoon of July 30th. Coinkite, one of the most reputable hardware wallet manufacturers, was revealed to have a critical bug in the way it generated secure private keys for its Bitcoin hardware wallets. Industry experts believe AI was used in the breach.

Coldcard MK3 devices with firmware version 4.0.1 (March 2021) through 4.1.9 are the worst affected. 12- or 24-word seeds generated by the device that did not include user-generated dice rolls or a BIP 39 extra passphrase are vulnerable. 

Users who fit this category, who have bitcoins in an MK3 Coldcard and did not use the dice roll feature for extra entropy or the extra passphrase, should consider themselves at risk and move their coins as soon as possible from the wallets. Bitcoin Magazine technical writer Shinobi has published a guide on the topic, and Coinkite has also published a guide and advisory

The vulnerability was a specific line of code in the firmware, a low-level software codebase that controls the hardware. This firmware appears to be upgradable. The Coinkite advisory was updated this morning, advising users to upgrade device firmware for all three chips, MK3, MK4 and MK5 devices, including the Coldcard Q:

“Updated July 31, 2026 at 9:33 a.m. EDT: Fixed firmware is now available. Mk4 and Mk5 users must update to version 5.6.0 or later. Q users must update to version 1.5.0Q or later. For Mk3, update to version 4.2.0 or later.”

Coinkite also explained in their advisory that updating the firmware does not mean that the private and public keys generated by the vulnerable firmware before it are now secure; those keys remain vulnerable as they were effectively created with a weak password. After the firmware is updated, a new wallet needs to be created, and the funds need to be sent onchain to the new addresses to secure the funds. Coinkite wrote:

“Updating the firmware does not change or repair an existing seed. If your seed was generated before the fixed firmware version for your model, follow the migration guidance below unless the independent dice-entropy exception applies to you.”

Some Multisignature Wallets May Be At Risk

Peter Todd, Core contributor and cybersecurity engineer, today addressed specific edge cases for multi-signature wallets that use a threshold of Coldcards to secure funds. “Example case: you have a 2-of-3, with 2 Cold Cards, and a 3rd uncompromised device. If you move your funds, the moment your script is revealed for the first time – previously hidden behind the address hash – the attacker now knows enough to use the compromised 2 cold card keys to steal your funds.”

The transaction that reveals the multisig script might be unconfirmed, giving hackers enough time to create a competing transaction with a higher fee. Fortunately, such cases have a solution: the MARA mining pool can help in this case with their private mempool mining service, Slipstream; “because they promise to keep your transaction – and thus pubkeys – secret until they’re already in a block. Dramatically reducing the ability of the attacker to steal the funds,” said Todd. He added that “If you’ve already reused addresses, this isn’t relevant, and you should just try to move your funds ASAP. But if you haven’t, MARA may be able to help.”

Beyond The Immediate Crisis

NVK, one of the co-founders of Coldcard, published a long post on X with an initial analysis beyond the basic security steps needed to secure funds. In it, he wrote that the company is “committed to working with affected users who want to pursue a police report, insurance claim, or their own investigation”, including “a written incident summary specific to your loss and any transaction data we can share”. 

Beyond the immediate crisis, NVK pointed to a broader tech shift as the hacking capabilities of AI begin to change previous cybersecurity dynamics and expectations. In the blog post he wrote: 

“To every other developer: we believe this is a sober reality of the new AI paradigm. AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. If your firmware is open-source or has ever been public, assume it’s already being read by attackers and defenders alike.”

The hack and over 70 million dollars in estimated stolen funds in the past 24 hours are an effective bounty paid to hackers who are now likely auditing every wallet codebase available for vulnerabilities. While the Bitcoin and broader crypto industry has generally operated under the assumption that hackers will test their code, the development of AI models optimized for cybersecurity accelerates these processes. 

Industry experts gathered in a long X Spaces public call last night, discussing the topic for many hours. Beyond the immediate recommendations and answering questions to Bitcoin users throughout the long Spaces, analysis of what is likely to follow in the coming weeks was also discussed. Other wallet providers are likely to get probed, and especially open source projects which generate private key material will be tested. 

The X Spaces was not recorded, likely to preserve the privacy of everyone in the call; however, initial sentiment suggests companies will need to be auditing their code with the latest frontier models, as a matter of survival. The latest cybersecurity-oriented AI models by Anthropic, OpenAI, Moonshot’s Kimi K3 and others are already available to the public. Many companies in the Bitcoin industry already use these to test the integrity of the code, but some might not be, and the race to find vulnerabilities in wallet-facing code will certainly continue, especially in the following weeks.

Ultimately, today we grieve lost coins, and a state of introspection and careful review occurs. Beyond this now historic hack will be an open source self-custody industry and infrastructure that is likely to be orders of magnitude more secure, with very hard lessons learned. After all, every hacker with an AI agent is likely testing defenses now. 

Multi-vendor, Multi-key Wallets and Covenants

Future high sovereignty wallets, be it at the retail or corporate level, are likely to not depend on any single vendor. Multisignature wallets, when well done, can distribute vulnerability risks across different code bases, teams and hardware. 

User-generated entropy was also a major theme in the X Spaces discussed earlier, with dice roll-generated entropy brought up regularly as a solution. Coldcards, as well as other hardware wallets like Foundation Devices, guide users on how to add their own entropy properly; many dice need to be rolled, ideally north of a hundred individual rolls. Once done, however, dice rolls represent a non-software source of randomness for wallets that also separates users from the edge-case risks in software- or hardware-generated entropy.

Covenants a popular soft fork among a certain niche in the Bitcoin industry have also started to be brought up as further step to strengthen the self-custody industry. This upgrade to the Bitcoin consensus which might be hard fought if achieved at all, could give users important smart contract capabilities, such a wallet that can only send to a white list of addresses, something not possible in Bitcoin script today. 

This post Coinkite Releases Fixed Firmware After Coldcard Bug; AI Likely Involved In The Breach first appeared on Bitcoin Magazine and is written by Juan Galt.

COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED

By: Shinobi
31 July 2026 at 11:22

Bitcoin Magazine

COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED

First, yes, that is a very clickbait title and completely unusual. This is a real security issue. Here is the official announcement from Coinkite themselves posted yesterday, please read and verify the genuineness of the issue there.

TLDR: Coldcard MK2, MK3, MK4, MK5 and Q are being drained. A bug lets attackers find your seed phrase without any action on your part. Only wallets generated using the dice roll method are safe, assuming you rolled at least 50 dice. If you don’t know, don’t remember, or aren’t sure, move your funds immediately.

This is a critical issue that requires immediate action. If you used a Coldcard to generate a word seed and did NOT use the recommended 50+ dice rolls to provide your own entropy after the end of 2020, your word seed is not secure. It was generated without a sufficient amount of randomness, and can be brute forced by a malicious attacker. Wallets are actively being drained now. This issue also affects any ephemeral keys and session keys for Clone Coldcard or Key Teleport features, and BIP 85 seeds generated from a compromised seed. YOU MUST STILL MOVE YOUR FUNDS. 

This attack is being actively exploited, with around 1000 BTC seen moving on-chain connected to the vulnerability. 

Breath, and relax. You must move your funds to a new word seed, or a word seed generated by a different device, in order to secure your funds.

–   If you have another hardware wallet that is not a Coldcard, send your funds there. This is the quickest and simplest way to get them someplace secure.

–   If you do not have another hardware wallet, and only have a Coldcard, generate a passphrase using at MINIMUM six seed words from the BIP 39 word list. Use this guide to select your words for the passphrase, do NOT pick them yourself. Check your wallet fingerprint (or an address), power down your device, restart it and re-enter the passphrase. Confirm that the fingerprint (or address) matches, and send your funds to the passphrase wallet. This is not a permanent solution. This is simply giving you enough security that an attacker will not be able to brute force your keys in a matter of days, and you can generate a new seed without being in a state of panic. Make sure your passphrase is written down securely.

–   If you have no other options, or are uncomfortable with using the device at all, Nunchuck wallet available on mobile and desktop. Take your time, don’t rush yourself too fast, and make sure that all of your backups are done properly. After you have verified backups, send your funds to this wallet. If you are managing significant sums, Nunchuck has support for multisig. You can create one using multiple devices. Blockstream Green and Bluewallet are two other options for software wallets. 

Once your funds are secure, take a minute and relax. Coldcards are still safe to use as long as the word seed is generated securely. A firmware patch has been released here. Any word seed generated after this firmware update should be secure (and you can use the dice roll option too). If you have transferred your funds to a hot wallet, or something less secure, your Coldcard is safe to use after applying the firmware update and generating a new seed.

Once you have secured your own funds, stop and take stock. Reach out proactively to anyone you know who might be using a Coldcard that was vulnerable when they generated their seed. Inform them of the issue, and if needed (and you are capable) help walk them through migrating their funds. Everyone doesn’t pay attention to Bitcoin news on a regular basis, so many people might be unaware that they are even vulnerable.

Disclaimer: This article is for informational and educational purposes only and does not constitute financial, legal, or technical advice. Readers are solely responsible for managing their own private keys and executing fund transfers. Bitcoin Magazine and the author assume no liability for any loss of funds, technical errors, or operational missteps resulting from actions taken based on this content. Always independently verify security alerts directly through official project channels before taking action.

This post COLDCARD SECURITY RISK: IMMEDIATE ACTION REQUIRED first appeared on Bitcoin Magazine and is written by Shinobi.

Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen

31 July 2026 at 11:22

Bitcoin Magazine

Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen

The popular Bitcoin hardware wallet Coldcard product, made by Coinkite, is at risk following a $70 million hack.

Coinkite on Thursday admitted that its Coldcard Mk3 model was affected following the hack and advised users to move their funds. Then, on Friday, the company said that users of the later hardware devices Mk4, Mk5, and Q should also take precautions. 

Hackers on Thursday were first able to drain funds from 1,196 Bitcoin addresses because their private keys were not generated using sufficient entropy — or randomness. 

Since then, a total of 1,082.65 Bitcoins have disappeared from wallets, according to data from Galaxy Research and engineers at payments company Block. 

While Coinkite has not admitted that the hack is linked to their wallets, the company has said that a wallet seed generation bug in Coldcard products meant the hardware’s true random number generator wasn’t actually being used on certain firmware versions. 

Coinkite and other engineers in the Bitcoin space are still investigating reportedly ongoing drains still happening at the time of writing.

What actually happened 

A firmware bug in Coldcard Mk3 devices (starting with version 4.0.1 in March 2021) caused seed generation to fall back to a weak software PRNG instead of the hardware true random number generator, producing seeds with only ~40 bits of entropy rather than the intended 128.  This made private keys for many single-signature wallets (especially those created without dice rolls or a strong BIP-39 passphrase) predictable enough for attackers to brute-force.

A total of 594.5 Bitcoins worth over $35.7 million at today’s prices were moved to a new address from single-signature addresses on Thursday. 

🚨 NEW: Over 594 BTC worth $38 million was stolen from Bitcoin hardware wallet Coldcard users.

The attacker then moved around the BTC and consolidated 562 BTC into this address below.

Users are urged to review the company's official security guidance as soon as possible. ‼ pic.twitter.com/exD2Wax7CY

— Bitcoin Magazine (@BitcoinMagazine) July 31, 2026

More wallets were later drained, according to blockchain analysts, with the total now over $70 million. 

Various affected users shared their experiences on social media, with one saying that their Bitcoin had not been moved since 2021, and all of a sudden was swiped. 

Bitcoin engineers have since said that Coldcard products — specifically the Mk3 models — had  “faulty entropy in wallet generation,” meaning they did not use real randomness to create a seedphrase. 

What to do 

Developers in the Bitcoin space have since urged users to move their funds if they used a Coldcard. Coldcard has issued guidance for users to take, which can be found here.

The first post was the advisory and what users should do.

This second post has the technical details: what actually went wrong, why our reviews missed it, the impact across Mk3/Mk4/Q/Mk5, and what we changed.https://t.co/HshUxevCl3

( current evaluating Mk3 firmware release ) https://t.co/Yfdx4XcztA

— COLDCARD (@COLDCARDwallet) July 31, 2026

Coinkite first said that their Mk3 models were affected but then on Friday said that those who did not use sufficient entropy to create a seed — in this case, 50 dice rolls — should generate a brand-new seed on the updated device. Others have warned to ditch Coldcard completely to be sure their funds are safe. 

“Everything is fucked,” wrote Kevin Loaec, CEO of Bitcoin security company, Wizardsardine. 

“Every single mnemonic generated [via a Coldcard] since 2021 will be public in the next few days,” Loaec warns.

This post Coldcard Wallet Flaw Exposes Years of Bitcoin Seeds After $70M in BTC Stolen first appeared on Bitcoin Magazine and is written by Mathew Di Salvo.

❌
❌