Market Update
Coldcard Hacked: What Every Crypto Holder Should Take From It

Self custody cold wallets have long been treated as the gold standard of crypto security. Not your keys, not your crypto, keep your coins offline and there's nothing for an attacker to reach.
In late July 2026, that assumption took one of its heaviest knocks yet, not because someone broke into a device, but because of a flaw in how thousands of devices created their keys in the first place.
Here's a plain-English breakdown of what happened, who it affects, and what it teaches the rest of us about protecting crypto.

Key Takeaways
-
A firmware bug has compromised Coinkite's Coldcard hardware wallets, introduced in a March 2021 release and sitting in open-source code ever since.
-
The bug caused seed phrases to be generated with far less randomness than intended.
-
Attackers were able to reproduce those seed phrases offline and drain funds.
-
Galaxy Research has tracked roughly 1,367 BTC, close to US$89 million, swept from about 4,585 addresses across three waves.
-
No device was physically touched or remotely hacked. The weakness was in key generation, not in the wallet's offline storage.
-
Coinkite claims they have released a fixed firmware update for every affected model, but updating firmware does not repair a stolen seed phrase.
-
Affected users must generate a new seed phrase and move their funds.
-
The broader lesson: self-custody security depends on layers you never see, so redundancy and verification matter more than trusting any single device.

Quick Refresher: A wallet doesn't hold your crypto
Your crypto isn't in your wallet. Your crypto is an entry on the blockchain, which lives on thousands of computers worldwide. What your wallet actually holds is the private key, the secret that proves you're allowed to move that entry.
So a crypto wallet is like a keyring, not a purse. Once you see it that way, a "cold wallet" or “cold key”, stops being mysterious: it's just a question of where you keep the key.
Hot vs cold
Hot = the key sits on something connected to the internet. An exchange account, a phone app, a browser extension like MetaMask. Convenient for trading, but the key is sitting in an environment where malware, a phishing site, or a remote attacker could potentially reach it.
Cold = the key is kept somewhere with no internet connection at all. There's no remote path to it. To steal it, someone has to physically get to the thing.
That's the entire concept. "Cold" just means offline.

Hold up, Coldcard still got hacked
That's exactly why this hack is so unusual. Attackers didn't steal the physical thing.
The Coldcard wallets themselves made their secret keys badly, so the attacker just recreated them from scratch on their own computer.
Unpacking that
When you set up a Coldcard, the device invents your seed phrase for you. To be secure, that seed has to be genuinely random, picked from a pool so enormous that nobody could ever work through it. A properly generated seed phrase is made of a number with 39 digits. To put that in perspective: it's roughly the number of atoms that make up the entire planet. Guessing it is currently impossible.
On the affected Coldcards, that number had just 13 digits. Just over a trillion.
A trillion still sounds enormous, but a computer doesn't get tired. An ordinary graphics card can work through a trillion possibilities in a matter of hours. So the attacker didn't guess anything, they simply generated every seed the faulty devices could have produced, checked which ones held bitcoin, and helped themselves.
The seed phrase went from being one atom in the Earth to being one name in a phone book. A very long phone book, but one a computer can read cover to cover in an afternoon.

Attack timeline
On 30 July 2026, Coinkite, the Canadian manufacturer behind the Bitcoin-only Coldcard wallet, published a security advisory warning that seeds generated on certain firmware versions may have been created with insufficient randomness.
The opening wave on 30 July drained around 1,083 BTC from 1,196 addresses in roughly 41 minutes. Analysis from Chainalysis suggests the attacker went after the largest balances first, indicating they had studied the victim pool before beginning. Two further waves followed, with the third targeting much smaller balances, averaging around a tenth of a bitcoin per victim, and using more complex, harder-to-trace transaction patterns.
Coinkite CEO Rodolfo Novak publicly apologised and took full accountability for the firmware bug, acknowledging that internal review processes had failed to catch it.

The wider lesson: how to keep your crypto safe
Among many other things, here are a few ways to stay safe while using self-custody:
Understand where your randomness comes from. A seed phrase is only as strong as the process that made it. Where a device offers user-supplied randomness, dice rolls, for example, using it means your security doesn't rest entirely on the manufacturer's code.
Use a passphrase. A strong, unique BIP-39 passphrase is an independent layer. In this case, it was the difference between exposure and safety for many holders. Back it up separately from your seed words, and never enter it on a website or untrusted machine.
Don't put everything in one basket. Binance founder CZ used the incident to argue for wallet diversification, and the point stands regardless of the messenger. Splitting holdings across different devices, vendors, or custody models means a single vendor's bug isn't a single point of total failure.
Consider multisignature for large balances. Every wallet drained in the first wave was single-signature. Multisig requires an attacker to compromise multiple independent keys.
Verify, don't assume. Check addresses on the device screen. Send test transactions. Confirm backups before funding a wallet.
Stay subscribed to your vendor's security channels. The people who moved fastest here were the ones who saw the advisory early. Security research firm Blockaid notes that most crypto losses in the first half of 2026 came not from smart contract exploits but from compromised keys and operational security failures, the unglamorous stuff.
Know that self-custody is a responsibility, not a setting. For some holders, that responsibility is worth it. For others, a regulated custodian is a reasonable trade-off. Neither answer is wrong; what matters is choosing deliberately rather than by default.

This article is general information only and does not constitute financial, investment or security advice. It does not take into account your objectives, financial situation or needs. Figures and guidance were accurate at the time of writing and this situation is ongoing, always refer to Coinkite's official advisory for the latest instructions. Consider your own circumstances and seek independent advice before making decisions about your assets.






