A crypto hack targeting a firmware flaw in the Coldcard Bitcoin hardware wallet has drained at least 1,367 BTC, worth approximately $86M at current prices, from more than 4,500 cold storage addresses across three waves of attacks. The exploit never required physical access to a single device; it rebuilt private keys from scratch using mathematics.
Galaxy Research: Three Suspected Attacks on Coldcard-Generated Addresses Drain 1,367 BTC
Galaxy Research said its Bitcoin on-chain analysis identified three suspected attack waves targeting addresses generated by Coldcard, involving 4,585 addresses and a total of 1,367.05 BTC… pic.twitter.com/JdSz4W1TIk
— Wu Blockchain (@WuBlockchain) August 1, 2026
The central problem: Bitcoin self-custody promises that a key stored offline is unreachable. This attack proved that an unreachable key can still be unguessable, or not.
This story has unfolded as BTC USD sits at around $62,250, down -1.4% on this Monday morning as rumors swirl of Saylor lining up to dump more Bitcoin and the CLARITY Act deadline nearing, with no breakthrough looking likely.
$BTC is back into the $62,000-$62,500 level.
Hold this level, and Bitcoin could rally towards $65,000.
Lose this level, and BTC could drop to $60,000. pic.twitter.com/O877SmIdMU
— Ted (@TedPillows) August 3, 2026
How a Broken Random-Number Generator Broke Cold Storage
Coinkite, the Canadian maker of the Coldcard, confirmed that a March 2021 firmware error caused a vulnerability in its pseudo-random number generator (PRNG) during seed phrase creation.
Instead of using a hardware random-number generator, the firmware relied on the chip’s serial number and clock registers, reducing the potential keys from cryptographically vast to countable.
This allowed attackers to generate candidate seeds, derive corresponding Bitcoin addresses, and check them against the public blockchain without involving the victim’s device.
Galaxy Research detailed the first wave of attacks, where 1,082.65 BTC was stolen from 1,196 addresses in just 41 minutes on July 30.
A subsequent wave added around 208 BTC from 1,912 addresses using more sophisticated techniques, like batching multiple victims in a single transaction. Galaxy believes the attacks are orchestrated by a single operator but has not linked all three waves.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part’s nerdy, but here’s… pic.twitter.com/Lf9kJv9Jo4
— Jonathan Goodman (@itscoachgoodman) August 1, 2026
Trade BTC Markets on Kalshi and Claim Your FREE $25
Crypto Hack: Which Wallets Are Affected and What Owners Must Do Now
Coinkite initially warned users of Mk3 devices running firmware version 4.0.1 or later, later expanding this to include certain Mk4, Mk5, and Coldcard Q firmware versions. Emergency firmware updates were released, and CEO Rodolfo Novak apologized, taking “full accountability” for the bug.
However, updating the firmware does not fix the issue if a seed was generated on a vulnerable build; users must create a new seed and migrate funds to a new wallet. This incident highlights that the quality of entropy implementation is more crucial than brand reputation for hardware wallet security.
Jan3 CEO Samson Mow urged all Coldcard users to migrate their funds due to ongoing attacks. Block’s Clay Garrett noted that a paid account was used to identify source addresses during these attacks, and this information has been passed to authorities.
The Bigger Picture: Self-Custody Moves Risk, It Doesn’t Erase It
This crypto hack incident reflects a broader trend observed in 2026, where infrastructure and key compromise incidents, though fewer in number, lead to most dollar losses in the industry.
Speculation on X suggests AI tools may have played a role in discovering or exploiting the flaw, but this has not been confirmed by Coinkite or Block.
The Coldcard episode underscores a crucial principle: a hardware wallet’s strength relies on the randomness used for key generation. As noted by Galaxy Research, the decreasing cost of analyzing weak key spaces means the industry must improve its standards for entropy verification.
For those holding Bitcoin in self-custody, it’s essential to check your Coldcard firmware against Coinkite’s advisory, generate a new seed on updated firmware, and migrate funds to ensure safety.
EXPLORE: Best Crypto Presales With Asymmetric Upside in the Current Market
The post Coldcard PRNG Flaw Lets Attackers Reconstruct Private Keys: 1,367 BTC Drained appeared first on 99Bitcoins.