This website uses cookies
We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners who may combine it with other information that you’ve provided to them or that they’ve collected from your use of their services.
Consent Selection
Details
  • Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.
  • Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.
    • We do not use cookies of this type.

  • Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.
    • We do not use cookies of this type.

  • Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.
    • We do not use cookies of this type.

  • Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    • __emg_sidPending
      Maximum Storage Duration: 1 dayType: HTTP Cookie
      __emg_vidPending
      Maximum Storage Duration: 1 yearType: HTTP Cookie
      nl-read-countPending
      Maximum Storage Duration: PersistentType: HTML Local Storage
Cookie declaration last updated on 8/12/26 by Cookiebot
[#IABV2_TITLE#]
[#IABV2_BODY_INTRO#]
[#IABV2_BODY_LEGITIMATE_INTEREST_INTRO#]
[#IABV2_BODY_PREFERENCE_INTRO#]
[#IABV2_BODY_PURPOSES_INTRO#]
[#IABV2_BODY_PURPOSES#]
[#IABV2_BODY_FEATURES_INTRO#]
[#IABV2_BODY_FEATURES#]
[#IABV2_BODY_PARTNERS_INTRO#]
[#IABV2_BODY_PARTNERS#]
About
Cookies are small text files that can be used by websites to make a user's experience more efficient.

The law states that we can store cookies on your device if they are strictly necessary for the operation of this site. For all other types of cookies we need your permission.

This site uses different types of cookies. Some cookies are placed by third party services that appear on our pages.

You can at any time change or withdraw your consent from the Cookie Declaration on our website.

Learn more about who we are, how you can contact us and how we process personal data in our Privacy Policy.

Please state your consent ID and date when you contact us regarding your consent.
NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
NewsLayer PulseLIVEBTC$62,978+0.00%ETH$1,879-0.09%SOL$75.2-0.16%XRP$1+0.29%DOGE$0.07-0.02%ADA$0.179-0.60%Total Cap$2.27T+0.22%Layer Index43 Neutral
BreakingExternal ReportingUpdated 1時間前

Coldcard Wallet Hack Hits $114M Losses, Flip Bitcoin Golden Rule

A five-year-old firmware bug in Coldcard hardware wallets has led to four waves of automated sweeps draining an estimated 1,816 BTC — roughly $114 million — from over 5,200 addresses since July 30. Here’s what went wrong, why Bitcoin…

Coldcard Wallet Hack Hits $114M Losses, Flip Bitcoin Golden Rule
Publisher memeburn.com 5 分で読める
Image via memeburn.com

Market Context

Bitcoin

BTC

$62,978

+0.00% 24h

Layer Index

43

↑ 4 pts in 24h

A five-year-old firmware bug in Coldcard hardware wallets has led to four waves of automated sweeps draining an estimated 1,816 BTC — roughly $114 million — from over 5,200 addresses since July 30. Here’s what went wrong, why Bitcoin holders are now rushing coins back to exchanges, and what the on-chain panic reveals.

How a 2021 Bug Became a 2026 Crisis

The root cause traces back to a March 2021 firmware update for Coldcard Mk3 devices, built by Canadian manufacturer Coinkite. That update introduced a coding error in how the wallet generated seed phrases — the master password that controls access to your Bitcoin.

Instead of pulling randomness from the device’s hardware random number generator (RNG), the firmware fell back to a software-based alternative that produced far more predictable results. In security terms, the entropy dropped from a near-uncrackable 128 bits to roughly 40 bits on Mk3 devices. That’s the difference between a lock with trillions of combinations and one with about a million — still sounds like a lot, until a computer starts guessing.

The attacker didn’t need your device or your Wi-Fi password — just enough computing power to reconstruct possible seed phrases and check them against public blockchain data. Coinkite has since released emergency firmware patches, but for many, the warning came too late.

Four Waves, Five Days, $114 Million

Galaxy Research’s Alex Thorn has been tracking the attack in real time on X, and his breakdown paints a clear picture of escalation:

  • Wave 1 (July 30): 1,083 BTC swept from 1,196 addresses in just 41 minutes.
  • Wave 2 (July 31–Aug 1): An additional 76 BTC drained from roughly 1,477 addresses, targeting smaller balances.
  • Wave 3 (Aug 1–2): 208 BTC taken from 1,912 addresses using harder-to-trace transaction patterns.
  • Wave 4 (Aug 3): 449 BTC moved from 462 addresses — this time with replace-by-fee (RBF) enabled.

That last detail matters. RBF means victims who spot their address in Bitcoin’s mempool (the queue of unconfirmed transactions) can broadcast a higher-fee transaction and redirect the coins to safety before the block confirms. It’s a narrow window — minutes, not hours — but it’s real.

None of the four waves touched multisignature wallets. The flaw targets single-key setups only, which means the seed phrase security approach you use matters as much as the device itself.

The Anti-FTX Trade

When FTX collapsed in November 2022, investors pulled crypto off exchanges in a panic. Coldcard sales surged. Hardware wallets became a symbol of financial sovereignty. Now the opposite is happening.

CryptoQuant research head Julio Moreno reported that sub-1 BTC transfers hit 39,600 BTC on July 31 — just 300 BTC below the panic spike from the day FTX filed for bankruptcy. But this time, the coins are flowing toward exchanges, not away from them. Daily active addresses surged from 645,000 to nearly one million overnight. People aren’t accumulating. They’re evacuating.

The Coldcard hack didn’t break Bitcoin’s protocol — the blockchain itself is fine. But it exposed that the tools promising to protect you from exchanges carry their own category of risk: firmware integrity, supply chain security, and the invisible processes you never interact with but completely depend on.

AI May Have Found What Humans Missed

There’s a disturbing footnote to this story. Coinkite acknowledged that the attacker likely used AI to comb through its open-source code and identify the flaw. The company admitted its own AI-assisted code review, conducted weeks earlier, missed the same bug.

Galaxy’s Thorn described the sweeps as likely LLM-orchestrated — large language models may have helped automate the process of testing seed phrases against on-chain data at scale. This fits a broader pattern: crypto hacks in Q2 2026 set a record with 83 incidents, and increasingly the most damaging attacks target human infrastructure rather than smart contract code.

It’s a sobering inversion. The same AI tools that should help developers catch bugs faster are also helping attackers find and exploit them first.

What Coldcard Users Should Do Right Now

If you created a seed on a Coldcard Mk3 running firmware 4.0.1 or later, treat your wallet as compromised. Install the patched firmware, generate a completely new seed phrase, and transfer everything to the new address. Don’t just import your old seed into another wallet — the seed itself is the problem.

For anyone setting up a crypto wallet today, this is a clear reminder that hardware doesn’t mean invincible. Multisig setups, passphrase protection, and diversified storage remain the strongest defenses — not any single device brand.

FAQs

What is replace-by-fee (RBF) and how can it help Coldcard victims? 

RBF is a Bitcoin feature that lets you replace an unconfirmed transaction by broadcasting a new one with a higher fee. If you spot an unauthorized transaction from your address still sitting in the mempool, you can outbid the attacker and redirect your coins to a safe address. You’ll need a wallet that supports RBF and you’ll have to act within minutes, before the transaction confirms in a block.

Are other hardware wallets like Trezor or Ledger affected by this exploit? 

No. The flaw is specific to Coldcard’s firmware, not to hardware wallets in general. Trezor and Ledger use different architectures and random number generation processes. That said, every hardware wallet relies on firmware that could contain undiscovered bugs, which is why regular updates and multi-layer security practices matter for all devices.

Could North Korea’s Lazarus Group be behind the Coldcard attack? 

So far, no attribution has been confirmed. While state-backed groups like Lazarus have been linked to major DeFi hacks in 2026, researchers at Galaxy say the Coldcard sweeps don’t follow the same laundering patterns. Multiple independent attackers may be exploiting the same vulnerability in parallel.

Is self-custody still safe after this hack? 

The incident exposed a product flaw, not a fundamental failure of self-custody. Casa CEO Nick Neuman argued that distributed ownership actually gave users time to react and move funds. The key takeaway is that self-custody requires ongoing vigilance — firmware updates, passphrase use, and strong seed storage practices — rather than a set-and-forget approach.

What happened to Bitcoin’s price after the Coldcard exploit? 

Bitcoin dipped below $63,000 during the weekend as the news spread, though the price impact has been modest relative to the scale of the theft. The bigger on-chain signal was the surge in small-holder exchange deposits, which hit levels not seen since November 2022 — a defensive move rather than a sell-off.

Vincee Cole

Vincee Cole is a technology journalist with four years of experience covering the full spectrum of modern tech — from consumer devices, artificial intelligence, to quantum computing, blockchain, and digital assets. His reporting cuts through complexity to deliver stories that are sharp, grounded, and relevant to both general readers and industry insiders. Previously, he worked with fintech research teams across Southeast Asia, analysing how emerging technologies are reshaping financial systems at scale.

Visit Profile

速報

速報を見逃さない

Advertisement

House — Advertise on NewsLayer
NewsLayerAd

Sourced by

Originally reported by memeburn.com

NewsLayer coverage based on externally reported material.

The Daily Brief

The onchain economy, before your day starts.

Curated markets, onchain insights, and key headlines — delivered every weekday morning.

Weekdays · Free · ~5 minute read

関連記事