# Coldcard Cold-Wallet Theft Nears $89 Million as a Five-Year-Old Firmware Bug Reproduces Users' Keys

Galaxy Research counts three rounds that drained about 1,367 bitcoin from 4,585 single-signature wallets, all traceable to seeds that a 2021 update generated with predictable software randomness.

- Published: 2026-08-02T05:31:41.327Z
- Canonical: https://polylog.news/crypto/2026-08-02/coldcard-cold-wallet-theft-nears-89-million-as-a-five-year-o
- Publisher: Polylog (Crypto desk)
- Section: crypto
- Sources: [CoinDesk](https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million), [Bitcoin Magazine](https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack), [Polylog editors](https://polylog.news)

An attacker has drained roughly 1,367 bitcoin, worth close to $89 million at current prices, from about 4,585 Coldcard hardware wallets, according to [CoinDesk's account of Galaxy Research's on-chain mapping](https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million). The loss started at $38 million late last month and has since moved through three separate rounds. The most recent round targeted smaller balances and used more complex transaction patterns to collect the funds.

The root cause is not a broken chip or a stolen recovery phrase. A firmware integration error shipped in March 2021 routed seed generation on affected Coldcard devices to a deterministic software pseudorandom number generator instead of the STM32 chip's hardware random number generator. Because the software fallback was seeded from fixed factory metadata and predictable clock values, an attacker could reconstruct the private keys off-chain without ever touching a victim's device, seed card, or computer. Every drained wallet used a single signature and held more than roughly 0.15 bitcoin, and the affected coins span 2021 through 2026, which matches the age of the flaw.

Coinkite, Coldcard's maker, has [released fixed firmware](https://bitcoinmagazine.com/business/coinkite-releases-fixed-firmware-after-coldcard-bug-ai-likely-involved-in-the-hack) and urged users to move funds to newly generated wallets. The company's founder, who goes by NVK, said that code review assisted by artificial intelligence can now find hidden bugs faster than experienced human auditors, and that the same kind of tooling may have helped whoever found this one. [Watcher Guru put the running total above $88 million](https://t.me/WatcherGuru/14511) before the third round pushed it higher.

The neutral read is that this is a failure of the randomness used to create the keys, not a compromise of the secure-element hardware. That distinction matters for who is exposed. The certified hardware operated correctly. The bug was in how the software requested randomness, which means no amount of physical tamper resistance would have protected a key that was predictable from the moment it was created.

## What this means

The loss comes from the randomness used to generate the keys, not from device theft, so it affects exactly the population that chose self-custody hardware for safety. Holders of any single-signature wallet created on affected firmware between 2021 and 2026 are exposed, and dormant balances are the most valuable targets because those keys were always reconstructable. Each incident of this kind pushes risk-averse holders toward multisig, custodians, and spot exchange-traded funds (ETFs), which is the opposite of the self-custody promise that hardware wallets are sold on.

## What to watch

- Whether Galaxy Research or chain-analytics firms attribute the three rounds to one operator or several, which would tell holders whether the exploit method has spread beyond a single actor.
- Whether other wallet makers that use software randomness fallbacks disclose audits, since the same integration mistake could exist elsewhere.
- Net flows into spot bitcoin ETFs and custodial products in the days after the theft, a direct measure of whether confidence in self-custody is weakening.
