skip to content

Research • August 07, 2026

Your Keys, Not Your Coins: Coldcard Wallets Hacked for $130m and Counting

Removing a third-party custodian does not remove custody risk; it transfers that risk to the hardware, software, and key-generation processes on which the holder depends.

This article originally appeared in Galaxy Research's weekly newsletter. Subscribe to get timely insights delivered to your inbox every Friday morning.

Starting July 30, attackers have drained wallets hosted on Coldcard devices across multiple escalating waves: roughly 1,082 BTC by Aug. 1, then approximately 284 BTC in the next two waves, with a fourth wave possibly underway. Galaxy

Research now estimates at least 15 separate attackers are exploiting the bug independently, up from the handful of coordinated operators we initially identified, with total losses tracked near $130 million as of Aug. 4.

The vulnerability originated in Coldcard’s seed-generation process. Normally, the device would draw entropy (a measure of randomness) for a new seed phrase from a dedicated hardware random-number generator embedded in its chip. A firmware bug introduced in a March 2021 (yes, five years ago) release instead routed part of that process through a software fallback. That fallback was seeded only by the device’s fixed information and its timer/clock registers, rather than a strong source of new randomness.

As a result, affected seeds that should have contained approximately 128 bits of randomness may have had an effective entropy of only around 40 bits for affected Mk2 and Mk3 devices and 72 bits for newer Mk4, Q, and Mk5 devices. At that level, an attacker with an approximate understanding of the device identifier and seed-generation timing could generate candidate seeds offline and compare the corresponding addresses against the public blockchain. Physical access to the wallet was not required.

Coinkite, the Canadian manufacturer of Coldcard, released emergency firmware updates, but the remediation is prospective rather than retroactive. The patches can protect seeds generated after installation, but they cannot strengthen a seed that was already created using vulnerable firmware. Those seeds remain permanently susceptible to brute-force recovery. Affected users have therefore been advised to generate an entirely new seed on patched hardware and migrate their assets to new wallets.

Our take

Self-custody is often presented as the cleanest way to eliminate counterparty risk: investors hold their own private keys and are therefore insulated from the failure of an exchange, custodian, or other intermediary. The Coldcard exploit exposes the other side of that trade-off. Removing a third-party custodian does not remove custody risk; it transfers that risk to the hardware, software, and key-generation processes on which the holder depends.

The incident complicates one of the central assumptions behind self-custody. The maxim of “not your keys, not your coins” frames control of the private key as the primary safeguard against theft or confiscation. In this case, however, the hardware wallet itself introduced the vulnerability at the point of key creation. One user said he kept a Coldcard in a bank safe-deposit box, never connected it to the internet, and nevertheless lost 18.25 BTC in seven minutes. As this victim mused, “Perhaps the hardest part about this is that I did everything right.” The failure occurred before standard operational-security practices could offer any protection.

Institutional-grade custodians, such as Coinbase Custody and Fidelity Digital Assets, typically employ controls including offline key generation, multisignature authorization, geographically distributed key material, and segregated cold-storage accounts. These measures do not eliminate custody risk, but they are designed to prevent the failure of a single device or location from resulting in a total loss. In effect, they apply the same risk-distribution principle as multisignature self-custody, but embed it in a regulated and operationally controlled custodial framework.

The more durable lesson is narrower but still significant: possession of a private key is only as secure as the process and infrastructure used to create it.

Galaxy's head of firmwide research, Alex Thorn, has been tracking the onchain movement of coins stolen in the Coldcard hardware wallet exploit and working with Bitcoin community members to gather intel that might help authorities catch the thieves and recover victims' BTC. If your Coldcard device was hacked, DM @intangiblecoins on X. More than 200 victims have reached out, but Alex's AI agent is triaging messages, and he will eventually reply to all.

You are leaving Galaxy.com

You are leaving the Galaxy website and being directed to an external third-party website that we think might be of interest to you. Third-party websites are not under the control of Galaxy, and Galaxy is not responsible for the accuracy or completeness of the contents or the proper operation of any linked site. Please note the security and privacy policies on third-party websites differ from Galaxy policies, please read third-party privacy and security policies closely. If you do not wish to continue to the third-party site, click “Cancel”. The inclusion of any linked website does not imply Galaxy’s endorsement or adoption of the statements therein and is only provided for your convenience.