A firmware vulnerability in Coldcard hardware wallets has led to the draining of over 1,800 Bitcoin (BTC) since Thursday. The flaw, which originated in 2021, made wallet seeds guessable, according to reporting by The Defiant. This incident raises concerns about the security of self-custody solutions in the cryptocurrency market.
Attackers exploited this vulnerability in a series of events, with the latest wave beginning on Thursday. The Defiant reported that this represents a fourth attack wave. Users of affected Coldcard wallets face potential loss of their digital assets.
This report is based on unconfirmed reporting; the desk will update it as confirmation arrives.
Firmware Vulnerability Details
A firmware vulnerability shipped in 2021 made Coldcard wallet seeds guessable. This design flaw allowed malicious actors to potentially access and drain funds from affected wallets. The specific technical details of the bug beyond 'seeds guessable' were not immediately available.
Scale of Bitcoin Drained
Attackers have drained more than 1,800 BTC due to this vulnerability. The latest wave of attacks began on Thursday, according to The Defiant. Crypto Briefing reported that over 1,367 BTC were drained from air-gapped wallets in one exploit.
Ongoing Attack and Recovery Window
The latest sweep of attacks may still offer a recovery window for some victims. Users might be able to outbid attackers in the mempool to rescue their coins. This process involves submitting a transaction with a higher fee to prioritize its confirmation over the attacker's transaction.
Impact on Self-Custody Confidence
The incident impacts confidence in self-custody solutions, according to Crypto Briefing. The exploit of a hardware wallet designed for security raises questions about the reliability of such devices. Self-custody allows users to maintain direct control over their private keys and digital assets.
Expert Commentary on Bitcoin's Principles
Jameson Lopp stated that the exploit challenges Bitcoin's 'don't trust, verify' principle, as reported by The Block. This principle emphasizes the importance of users independently verifying transactions and software. The Coldcard incident suggests potential limitations in applying this mantra to hardware security.
Air-Gapped Wallets and Security Concerns
The exploit also changes the conversation about offline security for air-gapped Bitcoin wallets, according to Decrypt. Air-gapped wallets are designed to operate without direct connection to the internet. This isolation is intended to enhance security by reducing exposure to online threats.
Implications for Wallet Security
The vulnerability highlights the ongoing challenges in securing cryptocurrency holdings. Even devices designed for high security can contain flaws. This incident underscores the need for continuous auditing and robust security practices in the development of hardware wallets.
Broader Market Reaction
The incident occurred as Bitcoin rebounded to $64,000, according to Crypto Briefing. The security breach rattled self-custody confidence despite the broader market movement. Bitcoin's price was $63678.893652866886 as of 2026-08-03T21:15:57.773839+00:00.
Developer Auditing and Uncovering Flaws
The exploit helps in uncovering vulnerabilities faster, according to Decrypt. It encourages developers to audit their code more thoroughly. This process can lead to improved security measures in future hardware wallet designs.
The Role of Firmware in Security
Firmware is crucial for the operation of hardware wallets. A flaw in firmware can compromise the entire security architecture of a device. The Coldcard incident demonstrates the critical importance of secure firmware development and updates.
Market context
The market reacted to news of a Coldcard firmware vulnerability that made wallet seeds guessable, leading to the draining of over 1,800 BTC since Thursday. The Defiant reported that Coldcard thefts approached $114 million. This development occurred as Bitcoin rebounded to $64,000, according to Crypto Briefing. Bitcoin traded at $63678.893652866886 as of 2026-08-03T21:15:57.773839+00:00, showing a 24-hour change of 0.33291240505426684%.
The exploit, which Crypto Briefing stated drained over 1,367 BTC from air-gapped wallets, rattled self-custody confidence. Jameson Lopp commented that the Coldcard exploit exposed limits of Bitcoin’s ‘don’t trust, verify’ mantra, as reported by The Block. Decrypt noted that the incident changed the conversation about offline security for air-gapped Bitcoin wallets. The market impact was bearish, reflecting concerns about the reliability of hardware wallets and broader implications for security within the crypto ecosystem.
Historical context
The compromise of hardware wallets due to firmware vulnerabilities has historical parallels in the cryptocurrency space. Past incidents have involved security flaws in hardware or software that led to unauthorized access to funds. These events often highlight the tension between user convenience and robust security, particularly in self-custody solutions.
Such episodes frequently lead to a re-evaluation of security practices within the crypto community, prompting developers to enhance auditing processes and users to scrutinize the security claims of hardware devices. The resolution of these situations typically involves firmware updates to patch vulnerabilities, alongside efforts to mitigate losses for affected users where possible. The impact on market confidence in specific hardware or the broader self-custody paradigm is a recurring theme.
What it means for the industry
The Coldcard incident impacts the perception of hardware wallet security. It raises questions about the reliability of self-custody solutions, even those considered robust. This event may lead to increased scrutiny of firmware development and auditing practices across the hardware wallet industry. It could also prompt users to re-evaluate their self-custody strategies and diversify their security measures.
Expert context
Jameson Lopp stated that the exploit challenges Bitcoin's 'don't trust, verify' principle, as reported by The Block.
Key takeaways
- A firmware vulnerability in Coldcard wallets, present since 2021, made wallet seeds guessable.
- Attackers have drained over 1,800 Bitcoin (BTC) since Thursday due to this vulnerability.
- The latest wave of attacks began on Thursday, representing a fourth attack wave.
- Victims may still have a chance to recover funds by submitting higher-fee transactions in the mempool.
- The incident challenges Bitcoin's 'don't trust, verify' principle, according to Jameson Lopp as reported by The Block.
- The exploit impacts confidence in self-custody solutions and changes discussions about air-gapped wallet security.
The Coldcard firmware vulnerability highlights persistent security challenges in the cryptocurrency ecosystem. The incident underscores the need for rigorous security audits and continuous vigilance in hardware wallet development. Future developments will likely focus on enhancing firmware integrity and user verification processes. The industry will monitor the effectiveness of mempool outbidding for victim recovery. Further reports on the technical specifics of the vulnerability are anticipated.
Newsroom intelligence
The short version
A firmware vulnerability in Coldcard wallets, active since 2021, allowed attackers to guess seeds. This flaw led to the draining of more than 1,800 BTC since Thursday. Victims may still have an opportunity to recover funds by outbidding attackers in the mempool.
AI-assisted summary · reviewed against the cited reporting
Market snapshot
In this story
BitcoinBTC
Galaxy Digital
Wallet
United States
Layer 2
Bridge
Custody
Spot ETF
How this story developed
- reportBitcoin Magazine
Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit
Bitcoin Magazine Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit Triggered by the Coldcard RNG vulnerability that drained over $100 million, the Bitcoin Red Team led by Calle and Rob Hamilton has already filed 4,962 findings across 390 open-source projects using frontier AI models. This post Bitcoin Red Team Finds 85 Critical Flaws Across 390 Open Source Repos After Coldcard Exploit first appeared on Bitcoin Magazine and is written by Juan Galt .
- reportCoinDesk: Bitcoin, Ethereum, Crypto News and Price Data
Coldcard exploit could boost demand for regulated bitcoin exposure, analysts say
Cantor sees positive read-through for crypto custody providers, while FRNT says the breach could drive some investors toward bitcoin ETFs.
- reportUnchained
Coldcard Bitcoin Theft Tops $100 Million as Galaxy’s Alex Thorn Tracks a Fourth Wave
Speaking on Bits + Bips, the Galaxy Digital researcher said Coldcard victims "did nothing wrong," noting he has found roughly 14 more attacker patterns not yet made public. The post Coldcard Bitcoin Theft Tops $100 Million as Galaxy’s Alex Thorn Tracks a Fourth Wave appeared first on Unchained .
- reportCointelegraph.com News
Bitcoin ETFs log inflows as cold wallet hack reignites custody debate
US spot Bitcoin ETFs drew $382 million in two-day inflows, with Galaxy’s Bitcoin ETF returning to gains as the Coldcard incident renewed custody concerns.
- reportCryptoSlate
Coldcard’s $130 million crisis is pushing Bitcoin back into Wall Street’s hands
The Coldcard hardware wallet exploit has resulted in the theft of at least 1,596 BTC from about 7,300 addresses as users continue moving funds from potentially vulnerable wallets. Galaxy Research said the confirmed losses came from three major attack waves and 14 smaller incidents. The firm has also identified a possible fourth wave that could […] The post Coldcard’s $130 million crisis is pushing Bitcoin back into Wall Street’s hands appeared first on CryptoSlate .
- reportDecrypt
Ledger Says Coldcard Exploit Shows Bitcoin Wallet Security Must Adapt to AI
Ledger CTO Charles Guillemet says the Coldcard exploit underscores why certified hardware randomness matters—and why AI is reshaping wallet security.
- reportCrypto Briefing
Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb
The Coldcard exploit underscores the critical need for rigorous security audits in crypto hardware, reigniting debates on self-custody safety. The post Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb appeared first on Crypto Briefing .
- reportDecrypt
Coldcard Bitcoin Exploit Explained: Entropy, How Keys Are Generated, and Why Bits Matter
A flaw in Coldcard wallets cost Bitcoin holders more than $100 million—and reopened an old fight about whether you can trust dice.
- reportProtos
15 attackers now draining vulnerable Coldcard wallets, report
Coldcard’s hardware wallet bug has attracted at least 15 attackers who who've stolen BTC from thousands of victims. The post 15 attackers now draining vulnerable Coldcard wallets, report appeared first on Protos .
- reportBitcoin Magazine
Nearly $32 Million in ‘Dormant’ Bitcoin Moves After Coldcard Hack Reaches Estimated $130M
Bitcoin Magazine Nearly $32 Million in ‘Dormant’ Bitcoin Moves After Coldcard Hack Reaches Estimated $130M Bitcoin worth close to $32 million moved for the first time in 12 years yesterday. This post Nearly $32 Million in ‘Dormant’ Bitcoin Moves After Coldcard Hack Reaches Estimated $130M first appeared on Bitcoin Magazine and is written by Mathew Di Salvo .
- reportCointelegraph.com News
At least 15 attackers exploited Coldcard vulnerability: Galaxy
Galaxy said that at least 15 different attackers have exploited the Coldcard vulnerability, which may have been avoided with just $2 worth of AI hardening, according to Dragonfly’s managing partner.
- reportCryptoPotato
Coldcard Urges Users to ‘Carefully Move Funds’ as Exploit Losses Mount
Some reports claimed that the stolen money is somewhere around $130 million already. And, it's still increasing.
Sources & verification
Corroborated across 12 independent domains
- 1.A firmware vulnerability in Coldcard hardware wallets has led to the draining of over 1,800 Bitcoin (BTC) since Thursday.The Defiant · published
- 2.The flaw, which originated in 2021, made wallet seeds guessable, according to reporting by The Defiant.The Defiant · published
- 3.The Defiant reported that this represents a fourth attack wave.The Defiant · published
- 4.## Firmware Vulnerability Details A firmware vulnerability shipped in 2021 made Coldcard wallet seeds guessable.The Defiant · published
- 5.## Scale of Bitcoin Drained Attackers have drained more than 1,800 BTC due to this vulnerability.The Defiant · published
- 6.Crypto Briefing reported that over 1,367 BTC were drained from air-gapped wallets in one exploit.Crypto Briefing · published
- 7.## Expert Commentary on Bitcoin's Principles Jameson Lopp stated that the exploit challenges Bitcoin's 'don't trust, verify' principle, as reported by The Block.The Block · published
- 8.## Broader Market Reaction The incident occurred as Bitcoin rebounded to $64,000, according to Crypto Briefing.Crypto Briefing · published
- 9.Bitcoin's price was $63678.893652866886 as of 2026-08-03T21:15:57.773839+00:00.Crypto Briefing · published
- 10.The market reacted to news of a Coldcard firmware vulnerability that made wallet seeds guessable, leading to the draining of over 1,800 BTC since Thursday.The Defiant · published
- 11.The Defiant reported that Coldcard thefts approached $114 million.The Defiant · published
- 12.This development occurred as Bitcoin rebounded to $64,000, according to Crypto Briefing.Crypto Briefing · published
Last verified · Not financial advice. See our editorial policy and risk disclosure.
Questions readers are asking
- What caused the Coldcard wallet vulnerability?
- A firmware vulnerability, present since 2021, made Coldcard wallet seeds guessable. This design flaw allowed malicious actors to potentially access and drain funds from affected wallets, compromising the security of the hardware device.
- How much Bitcoin was drained due to the Coldcard vulnerability?
- Attackers drained more than 1,800 BTC due to the Coldcard firmware vulnerability. The latest wave of these attacks began on Thursday, with one exploit alone reportedly draining over 1,367 BTC from air-gapped wallets, according to Crypto Briefing.
- Can victims recover funds from the Coldcard exploit?
- Some victims may still have a recovery window. Users might be able to outbid attackers in the mempool to rescue their coins. This involves submitting a transaction with a higher fee to prioritize its confirmation over the attacker's transaction.
- How does this incident affect confidence in self-custody?
- The incident impacts confidence in self-custody solutions, according to Crypto Briefing. The exploit of a hardware wallet designed for security raises questions about the reliability of such devices, challenging the 'don't trust, verify' principle, as reported by The Block.
- What are air-gapped wallets and how were they affected?
- Air-gapped wallets are designed to operate without direct internet connection to enhance security. However, the Coldcard exploit affected these wallets, with over 1,367 BTC drained from them in one instance, according to Crypto Briefing, changing the conversation about their offline security, as reported by Decrypt.
Story record
- Published
- Updated
- Reading time
- 4 min
- Beat
- Security
- Story status
- archived
- Sourcing
- 12 publishers · 12 domains
- Editorial score
- 88 / 100
- Quality score
- 92 / 100
Sign in and reach the end of the story to qualify. Rewards are awarded server-side after read verification. Rewards Rules.
Signal beyond the noise, once a day
One email with the stories that moved markets, what changed since yesterday, and what our newsroom is watching next.
The Crypto News Hub News Desk is our organizational newsroom byline for reports produced from verified public sources using the publication's automated research and quality controls. Reports flagged by those controls — for accuracy, sourcing, high risk or duplication — are held and reviewed by our human editors before publication. This byline does not imply that every piece was individually rewritten or signed off by a named journalist.
Reader feedback
We correct in the open. If something here is wrong, incomplete, or missing context, tell us and we will publish the correction with a version note.
