Coldcard Loses 1,816 BTC to 2021 Firmware Bug as Losses Hit $116M

August 6, 2026

A Five-Year-Old Bug Blows Open A “Cold” Wallet

The offline hardware wallet, long treated as the gold standard for self-custody bitcoin, is having its worst week on record. Between 30 July and 3 August, attackers drained roughly 1,816 BTC, worth about $116 million at the current bitcoin price, from more than 5,200 wallet addresses tied to Coinkite’s Coldcard device.

According to on-chain analytics firm TRM Labs, every affected wallet traces back to a single vulnerable firmware version released in March 2021, meaning the money was effectively lost the moment those seeds were created, years before the first coin moved.

How A 2021 Firmware Update Weakened Seed Generation

Every hardware wallet’s security rests on one job: generating a random seed phrase that no one else can guess. Coldcard’s affected firmware, version 4.0.1, contained a configuration error that quietly swapped the device’s dedicated hardware random number generator for a much weaker software fallback. According to TRM Labs, that single change collapsed the effective strength of a seed from 128 bits to as few as 40 bits.

In plain terms, a properly generated seed sits inside a search space so vast that guessing one is impossible. A 40-bit seed sits inside a space small enough for a modern GPU rig to churn through in a matter of hours. The wallets looked normal, felt normal, and signed transactions normally. They were simply guessable.

Four Waves, 5,200 Wallets, One Missing Line Of Code

The draining came in tightly clustered bursts rather than a slow trickle. TRM Labs recorded four distinct waves beginning on 30 July, with the first wave pulling around 594 BTC (worth roughly $38 million at the time) from about 500 wallets inside a 25-minute window. Three more waves followed over the next four days, each hitting a fresh batch of vulnerable addresses.

Transaction patterns differed across the waves, prompting TRM to conclude that multiple attacker groups appear to have discovered the same bug at similar times. Victim Jonathan Goodman told TechCrunch the outcome sounded simpler than it looked: “all because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.”

Solana Deposits now live on Digitap

Coinkite Halts Shipments And Warns Every Holder To Migrate

Coinkite, the Toronto company behind Coldcard, first published a security advisory on Thursday, 31 July, and expanded it on Saturday after the second wave landed.

The advisory instructed every user who had ever generated a seed on firmware 4.0.1 to migrate to a new seed phrase on a patched device, warned that a firmware upgrade alone does nothing for keys already produced under the bug, and confirmed that shipments of new units have been paused while remaining stock is destroyed and rebuilt. Security researchers at Block are credited with identifying the underlying flaw, though attackers had clearly already found it in the wild.

On-Chain Analysts Split On The Final Damage

Two of the biggest on-chain firms have landed on different estimates, and both may be right. TRM Labs’ 5 August breakdown put the running total at around 1,816 BTC, roughly $116 million. Elliptic’s chief scientist Tom Robinson separately told TechCrunch the same week that a figure closer to $130 million was “roughly correct”, suggesting continued draining after TRM’s cutoff and some ambiguity around which peripheral wallets belong to the same campaign.

Either way, analysts note this is now the largest hardware-wallet exploit ever recorded, comfortably eclipsing every previous cold-storage incident tracked by public dashboards.

Bitcoin Barely Flinches As Self-Custody Debate Reopens

Despite the size of the loss, the wider market has been almost eerily calm. Bitcoin has held in a narrow band through the week, and there has been no visible dump of the stolen coins into major exchanges, which usually explains why prices react to hacks of this scale. What has shifted, according to conversations across crypto Twitter and the latest crypto news cycle, is the self-custody debate itself.

For years, the industry line has been that a hardware wallet is the safe alternative to any custodial digital wallet. Coldcard’s exploit does not overturn that logic, but it does complicate it in a way beginners in particular need to understand: cold storage removes online attackers, not manufacturing risk.

The Real Lesson: Firmware Trust Is Never A One-Time Decision

The most uncomfortable part of the Coldcard episode is not the missing coins; it is the delay. A one-line configuration error sat inside shipped firmware for more than four years before anyone with the right tools noticed. Every layer that hardware wallets sell as an advantage, the offline signing, the tamper-resistant chip, the physical PIN, still worked exactly as advertised.

The security bar failed one step earlier, at the point where the seed was born. Analysts increasingly frame this as a wake-up call for the entire cold-storage industry: independent firmware audits, reproducible builds, and post-manufacture entropy checks were all treated as nice-to-haves before this week. After it, they look a lot more like the minimum.

Solana Deposits now live on Digitap

Share Article

Madiha Riaz

Madiha Riaz

Madiha is a seasoned researcher in cryptocurrency, blockchain, and emerging Web3 technologies. With a background in organic chemistry and a sharp analytical mindset, she brings scientific depth to decentralized innovation. Since discovering crypto in 2017 and investing in 2018, she’s been uncovering and sharing deep insights into how blockchain is redefining the digital asset landscape.