None of the four waves touched multisignature wallets. The flaw targets single-key setups only, which means the seed phrase security approach you use matters as much as the device itself.
The Anti-FTX Trade
When FTX collapsed in November 2022, investors pulled crypto off exchanges in a panic. Coldcard sales surged. Hardware wallets became a symbol of financial sovereignty. Now the opposite is happening.
CryptoQuant research head Julio Moreno reported that sub-1 BTC transfers hit 39,600 BTC on July 31 — just 300 BTC below the panic spike from the day FTX filed for bankruptcy. But this time, the coins are flowing toward exchanges, not away from them. Daily active addresses surged from 645,000 to nearly one million overnight. People aren’t accumulating. They’re evacuating.

The Coldcard hack didn’t break Bitcoin’s protocol — the blockchain itself is fine. But it exposed that the tools promising to protect you from exchanges carry their own category of risk: firmware integrity, supply chain security, and the invisible processes you never interact with but completely depend on.
AI May Have Found What Humans Missed
There’s a disturbing footnote to this story. Coinkite acknowledged that the attacker likely used AI to comb through its open-source code and identify the flaw. The company admitted its own AI-assisted code review, conducted weeks earlier, missed the same bug.
Galaxy’s Thorn described the sweeps as likely LLM-orchestrated — large language models may have helped automate the process of testing seed phrases against on-chain data at scale. This fits a broader pattern: crypto hacks in Q2 2026 set a record with 83 incidents, and increasingly the most damaging attacks target human infrastructure rather than smart contract code.
It’s a sobering inversion. The same AI tools that should help developers catch bugs faster are also helping attackers find and exploit them first.
What Coldcard Users Should Do Right Now
If you created a seed on a Coldcard Mk3 running firmware 4.0.1 or later, treat your wallet as compromised. Install the patched firmware, generate a completely new seed phrase, and transfer everything to the new address. Don’t just import your old seed into another wallet — the seed itself is the problem.
For anyone setting up a crypto wallet today, this is a clear reminder that hardware doesn’t mean invincible. Multisig setups, passphrase protection, and diversified storage remain the strongest defenses — not any single device brand.
FAQs
What is replace-by-fee (RBF) and how can it help Coldcard victims?
RBF is a Bitcoin feature that lets you replace an unconfirmed transaction by broadcasting a new one with a higher fee. If you spot an unauthorized transaction from your address still sitting in the mempool, you can outbid the attacker and redirect your coins to a safe address. You’ll need a wallet that supports RBF and you’ll have to act within minutes, before the transaction confirms in a block.
Are other hardware wallets like Trezor or Ledger affected by this exploit?
No. The flaw is specific to Coldcard’s firmware, not to hardware wallets in general. Trezor and Ledger use different architectures and random number generation processes. That said, every hardware wallet relies on firmware that could contain undiscovered bugs, which is why regular updates and multi-layer security practices matter for all devices.
Could North Korea’s Lazarus Group be behind the Coldcard attack?
So far, no attribution has been confirmed. While state-backed groups like Lazarus have been linked to major DeFi hacks in 2026, researchers at Galaxy say the Coldcard sweeps don’t follow the same laundering patterns. Multiple independent attackers may be exploiting the same vulnerability in parallel.
Is self-custody still safe after this hack?
The incident exposed a product flaw, not a fundamental failure of self-custody. Casa CEO Nick Neuman argued that distributed ownership actually gave users time to react and move funds. The key takeaway is that self-custody requires ongoing vigilance — firmware updates, passphrase use, and strong seed storage practices — rather than a set-and-forget approach.
What happened to Bitcoin’s price after the Coldcard exploit?
Bitcoin dipped below $63,000 during the weekend as the news spread, though the price impact has been modest relative to the scale of the theft. The bigger on-chain signal was the surge in small-holder exchange deposits, which hit levels not seen since November 2022 — a defensive move rather than a sell-off.
Vincee Cole
Vincee Cole is a technology journalist with four years of experience covering the full spectrum of modern tech — from consumer devices, artificial intelligence, to quantum computing, blockchain, and digital assets. His reporting cuts through complexity to deliver stories that are sharp, grounded, and relevant to both general readers and industry insiders. Previously, he worked with fintech research teams across Southeast Asia, analysing how emerging technologies are reshaping financial systems at scale.
Visit Profile