
Summary
- A 2021 firmware flaw in Coldcard generated predictable private keys; nobody touched the devices.
- Between July 30 and August 3, 2026, around 1,816 BTC (between 114 and 116 million dollars) were stolen in four waves.
- CoinKite, the company behind Coldcard, halted shipments, destroyed the affected inventory and published a migration guide.
- The case does not affect Bitcoin or other hardware wallet brands, but it reopens the question of self-custody versus custody on an exchange.
A flaw in how Coldcard generated the private keys for its wallets allowed someone to reconstruct those keys and drain accounts worth more than 100 million dollars in bitcoin. Here is what is known so far and what it means if you store your own crypto.
Between July 30 and August 3, 2026, roughly 1,816 bitcoin were stolen — between 114 and 116 million dollars depending on the source — from owners of Coldcard wallets, one of the hardware wallets used to store cryptocurrencies.
This was not a hack of the device. It was a flaw in how Coldcard generated private keys, dating back to a 2021 firmware update, which left those keys predictable for anyone who could reconstruct them without ever touching the wallet.
CoinKite, the company behind Coldcard, confirmed the problem, halted shipments and destroyed the inventory carrying the affected firmware. The case does not touch Bitcoin as a network or other wallet brands, but it does reopen a question that concerns anyone who stores their own crypto: how comfortable are you taking on that risk yourself?
Why the Coldcard case matters to any crypto owner
At first glance, the Coldcard case looks like a problem with one specific hardware wallet brand. But it became global news for reasons beyond the amount stolen.
It exposes an assumption many people take for granted when choosing how to store their crypto: that a hardware wallet and holding your own keys is all you need to be safe.
Binance founder Changpeng “CZ” Zhao summed up the dilemma on social media. He said he still believes in self-custody, but acknowledged that the decision places the entire security burden on the person who makes it.
That is, at bottom, the issue that matters to anyone holding crypto, whether or not they own a Coldcard: if you store your own private keys, a mistake by the device manufacturer — not just your own — can end up costing you your funds.
What a cold wallet is and what is supposed to make it secure
A cold wallet is a device that stores the private keys to your crypto completely disconnected from the internet, unlike a hot wallet, which is connected and ready to use from your phone or computer.
The logic behind this design is simple: if an attacker cannot reach your private key over the internet, they cannot steal it remotely either. That logic still holds against attacks that depend on a connection.
The problem in the Coldcard case was different: the private key was never truly random from the moment it was generated, so there was no need to connect to anything in order to reconstruct it.
What exactly went wrong with the Coldcards
Every wallet needs to generate a seed — a combination of words that works as the master key to your funds — through a process that must be completely unpredictable.
According to the security notice published by CoinKite, a configuration error in the Coldcard firmware, present since a March 2021 version, caused that process to use a software number generator with an identifiable pattern.
It is the difference between a safe with a randomly chosen combination and one whose combination follows a guessable formula. An attacker who reconstructed that formula was able to calculate, on their own computer and without touching any device, the private keys of thousands of addresses.
They then waited for funds to appear so they could move them first. CoinKite did not publicly detail the exact math behind the attack; the full technical notice is available on its site for anyone who wants to review the detail.
How the Coldcard theft grew, wave by wave
Analyst Alex Thorn, of Galaxy Research, documented the progress of the theft in real time. The first wave took place on July 30, 2026 and drained 1,083 BTC — around 70.2 million dollars at the time — from 1,196 addresses in roughly 41 minutes.
A second and third wave, over the following weekend, brought the running total to around 1,367 BTC, between 88.6 and 90 million dollars, from more than 4,500 addresses.
On the morning of Monday, August 3, Thorn identified patterns pointing to a fourth wave in progress, though he clarified that this was an analysis based on transaction behavior, without a direct report from a victim confirming it yet.
With that wave, the running total reached around 1,816 BTC: CoinDesk put it at close to 114 million dollars and Fortune at close to 116 million, a difference that comes down to the bitcoin price each outlet used, not a disagreement about the funds moved.
What CoinKite did and what to do if you own a Coldcard
CoinKite halted Coldcard shipments as soon as it confirmed the vulnerability, destroyed the inventory carrying the affected firmware at its facilities and contacted customers with orders already shipped directly. The company said it was coordinating with authorities to identify those responsible.
If you own a Coldcard, the official recommendation is to update to the corrected firmware, generate a completely new seed on the already-updated device and move your funds to that new seed.
Installing the patch on its own does not repair a seed that was already generated weakly. According to the same notice, a seed created with at least 50 fair and independent dice rolls, or protected with an additional passphrase, retains a layer of security against this specific problem.
CoinKite also clarified that its other products — SATSCARD, OPENDIME and TAPSIGNER — use a different codebase and are not affected.
Self-custody or exchange: the question the Coldcard case leaves behind
The Coldcard case does not say that self-custody is a bad idea. It says something more specific: that the security of a cold wallet depends as much on the manufacturer’s design as on your own decisions, and that being offline is no guarantee that everything else was done right.
That is why more and more people compare that model with leaving their funds on a regulated exchange, where the technical responsibility for generating and protecting the keys sits with the platform, not with the individual.
Neither option is automatically better: each involves a different kind of risk and control. It is worth reviewing, without alarmism, good security practices for your account and how the keys of whichever wallet you use were generated — or whether you would rather not have to think about it yourself.
Frequently asked questions
No, and the Coldcard case confirms it. A cold wallet reduces the risk of attacks that depend on an internet connection, but its security also depends on the manufacturer having generated the private keys in a truly random way. If that process fails, as it did with Coldcard, someone can reconstruct the keys without connecting to anything or touching the device.
There is no single answer, and it is worth being skeptical of any brand that advertises itself as the most secure without further detail. That guarantee does not depend on design alone: it depends on the manufacturer's transparency when failures like this one occur, on its track record of firmware audits, and on the user's own decisions, such as generating the seed with enough randomness — for example with physical dice — or protecting it with an additional passphrase.
In general, a cold wallet works as a door to your funds, not as the only place where they exist: what actually backs them is the seed phrase you generated when setting it up. If you stored that phrase separately and securely, you can recover your funds on another compatible device even if the original is lost or damaged. That is why official guides, including CoinKite's in this case, insist on not destroying previous backups until you confirm a migration completed correctly.
You cannot audit a manufacturer's firmware yourself, but you can reduce the risk: keep your wallet's firmware updated, use an additional passphrase (BIP-39) on top of your seed and, if you generate a new seed, do it with a verifiably random method, such as enough dice rolls, instead of relying solely on the device's generator. None of these measures guarantees absolute security, but they do add layers that are independent of the manufacturer.



