Bitcoin: The Complete Story of the Coldcard Vulnerability, from the $38 Million Heist to a $140 Million Toll
A month of cold sweats for Coldcard holders. On July 30, a five-year-old vulnerability allowed the siphoning of 594 BTC in just 25 minutes. Twenty-six days later, the tally shows up to 1,824 BTC stolen, amounting to approximately $140 million at current rates. Between the two, a story of waves, patchy fixes, and estimates that rise before stabilizing. A complete recap of the Coldcard vulnerability, from the first suspicious transfer to today’s tally. Key points of this article:
A security flaw in Coldcard wallets enabled the spectacular siphoning of 1,824 BTC, or about $140 million, in just a few weeks.
The five-year-old vulnerability highlighted critical flaws in key generation, threatening the security of users' funds.
Twenty-five Minutes, Five Hundred Addresses Drained {#h-twenty-five-minutes-five-hundred-addresses-drained}
It all begins on July 30, 2026. In just twenty-five minutes, approximately 594.5 BTC ($38 million) leaves nearly 500 addresses to a single consolidation address. The next day at 9:33 AM New York time, Coinkite, the manufacturer of the Coldcard hardware wallet, releases a corrected firmware.
However, correcting the code does not fix anything for the keys already generated: only a migration to a new seed (the secret phrase that protects the funds) can safeguard the old holders. JDC covered the story the very next day, citing Charles Guillemet, the technical director of Ledger, who feared a second wave now that the vulnerability was made public. He was right.
On the blockchain, the concern is immediately evident. 39,600 BTC change hands in small amounts, a level not seen since the collapse of FTX in November 2022. The parallel is striking, except that the market psychology is entirely different: while FTX triggered a panic sell-off and an exodus to self-custody, the Coldcard vulnerability conversely pushes some holders back towards centralized platforms. The price of Bitcoin, however, remains steady.
A Toll That Keeps Climbing {#h-a-toll-that-keeps-climbing}
On August 1, JDC already revises the figures upwards, reporting 1,083 BTC, $70 million, across 1,196 addresses. Galaxy Research, the on-chain analysis unit of Galaxy Digital, specifies a crucial detail: most of these funds had already been siphoned about thirty hours before Coinkite's public alert. So, not a new wave, but an accounting catch-up. Counting the damages of a live hack is a bit like assessing the damage of a storm before it has passed.
On August 2, Coindesk reports 4,500 affected addresses and losses nearing $89 million. On August 3, a fourth wave brings the total beyond 1,800 BTC, over $114 million, while Coinkite suspends its shipments. Bitcoin is then priced at $62,700, slightly down, with no direct link established to the incident.
| Date | Estimation | Precision |
|---|---|---|
| July 30 | ~38 M$ (594.5 BTC) | Initial observation, vague 1 |
| August 1 | ~70 M$ (1,083 BTC) | Reevaluation, not a new wave |
| August 2 | ~89 M$ (4,500 addresses) | Coindesk |
| August 3 | >114 M$ (1,800+ BTC) | 4th wave detected |
| August 4-5 | ~130 M$ (up to 2,055 BTC) | High estimate, Galaxy Research/Elliptic |
| August 24 | 114.7 to 140 M$ (1,789 to 1,824 BTC) | Refined estimate |
Source: Galaxy Research, Coindesk, TRM Labs, compiled by JDC.
The Coldcard Bug Explained Without Jargon
It remains to understand what went wrong. The flaw dates back to March 2021, nestled in a code library called libNgU. On certain firmware versions, the hardware random number generator of the wallet, which is supposed to ensure that a seed is impossible to guess, was short-circuited. Instead, a software generator took over, initialized with two predictable values: the device identifier and the internal timer at startup.
As a result, the entropy (the degree of unpredictability of a key, measured in bits) drops to about 40 bits on the Mk2 and Mk3 models, instead of the expected 128 bits. This makes the key crackable by brute force in just about fifteen days. Attackers only had to generate candidate keys, calculate the corresponding addresses, and watch for a match with a known Bitcoin address on the chain. No need to touch any device.
By comparison, Ledger relies on a hardware generator displaying 256 bits of entropy for its 24-word seeds. A truly unpredictable physical noise, not a reproducible formula.
A $2 AI and the Lesson Ledger Already Learned
On August 4, an associate of the crypto fund Dragonfly Capital attempts an experiment. To reproduce the flaw with general-purpose artificial intelligence, just to see. Total cost: about $2 of computation. Claude finds the problem in 8 minutes, GLM 5.2 in about twenty. The experiment took place after the public revelation of the bug, with the known context in hand. It does not prove that the AI discovered the original flaw, nor that it was used by the thieves. Coinkite and Galaxy Research still consider the hypothesis plausible. NVK, co-founder of Coldcard, goes so far as to say that AI-assisted code reviews now spot latent bugs faster than the most seasoned experts in the field.
One day later, JDC asks the uncomfortable question: what about the competitor? The answer lies in a comparison of entropy. On the Mk4, Mk5, and Q, which are slightly better off than the Mk3, it peaks at 72 bits. At Ledger, it rises to 256. The lesson is not that self-custody (keeping your own keys rather than entrusting them to a third party) is a bad calculation; it remains valid. It is the implementation that failed, not the principle. Notably, holders who activated a BIP-39 passphrase, an additional password to the seed, came out unscathed from the story.
Defense, Not Panic
On August 6, Galaxy Research estimates that 1,816 BTC were stolen across 5,294 addresses. In parallel, an unprecedented event occurs: 119,000 dormant BTC, which is 200 times the amount of the initial theft, change hands in three days, moved by holders who are uncertain about the security of their own hardware. Only about 10% go to exchanges. The rest migrate to new wallets. This is a defensive consolidation, not a rush for the exit, and the price of Bitcoin shows almost no trace of it.
This nervousness extends far beyond Coldcard holders. A wallet that has been dormant since December 2013, containing 500 BTC, awakens amid the turmoil without a direct link to the vulnerability. The post-Coldcard panic will even be cited later in the month as one of the explanations for another wave of awakenings of wallets that have been dormant for twelve to fifteen years, a well-known phenomenon in Bitcoin that the Coldcard crisis has brought back into focus.
The Patch That Fixes Nothing {#h-the-patch-that-fixes-nothing}
On August 21, JDC documents the paradox. Coinkite releases a new patch, this time supported by AI to track other anomalies in the code. However, no software patch can make a seed that has already been potentially guessed secret again. The patch protects future keys, not those already generated on vulnerable firmware. For those users, there is only one option: migrate everything to a new seed. The tally displayed at this date is $114 million.
Another, more discreet but equally revealing turnaround. Coinkite abandons its policy of automatically deleting customer data, which previously only retained the email and country of residence. The reason given is "legal obligations" related to the hacking, without details on the nature or duration of this retention. For a manufacturer that marketed the absence of logs as a privacy argument, this shift does not go unnoticed. Especially since Canadian holders seem to be among the most affected by the incident.
Where Is the Loot, One Month Later {#h-where-is-the-loot-one-month-later}
On August 24, Galaxy Research refines the note one last time. According to figures reported by Cryptotimes, the "high confidence" count stands at 1,789.28 BTC across 8,865 addresses, amounting to $114.7 million at the time of the thefts, and $138.8 million at the current rate. Including less certain cases, the total would rise to 1,824 BTC, approximately $140 million. Only 221 victim reports cover 44% of the total. The rest, Galaxy Research found on its own by scouring the chain, without any victims coming forward.
And then there is this figure, almost out of sync after a month of soaring. According to TRM Labs, 87% of the loot, or 1,561 BTC, still sleeps on the thieves' addresses. Only one notable deposit has been spotted, 64.9 BTC sent to a Wasabi transaction mixer, and 200 ETH sent to Tornado Cash. The transaction patterns differ from wave to wave, suggesting multiple independent attackers rather than an organized group. An unenviable ranking, the third largest crypto hack of 2026.
A month after the initial twenty-five minutes of panic, the lesson extends far beyond just the manufacturer. The personal protective equipment sector sells a simple promise: a component that does exactly what it claims, and that promise has cracked for five years without anyone noticing. The flaw even had an unexpected side effect, fueling a wave of awakenings of Bitcoin wallets that had been dormant for over a decade, with holders preferring to check their old keys rather than leave any doubt. "Ill-gotten gains never prosper," says the saying. A month after the heist, over 1,500 stolen bitcoins still lie dormant in unknown addresses, with no thief seemingly having found a way to benefit from them.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Stablecoin card spending crosses $10.9B

When do you pay taxes on crypto? Here's how box 3 works for you

Falcon-1024 Identified as Candidate for Bitcoin's Next Signature Scheme

Crypto stock tokens barely move over weekend, revealing markets become illiquid when Wall Street goes offline

US Debt: Grayscale Identifies 3 Cryptos That Could Benefit

How $739B in new US debt could absorb crypto’s liquidity before buybacks even reach Bitcoin

Memecoins and Politics: California Bans Officials from Creating Their Own Cryptocurrency

Popular Bitcoin wallets risk losing support for new hardware devices as critical security bridge stops accepting new devices

Crypto: Polygon Reveals Why the Austin and Kyoto Hard Forks Were Necessary

Bitcoin Rally Builds on $2.8 Billion ETF Inflows

Miner Vps Reviews: A Check on the Telegram Bot for Renting Mining Servers

Bitcoin Beach in El Salvador Sees Decline! Restaurant Receives Only 1 BTC Payment in a Month, Customers Return to Traditional Card Payments

Stablecoins: Banks Refuse Any Compromise on Yields

What is Nillion (NIL)? A Guide to Cryptocurrency and Blind Computing

What is StonkFun (STONK)? A Trading Guide and Explanation of Tokenized Stocks

After the Midterms, Will the 'Trump Trade' Backfire?

Macroeconomic Outlook for Next Week: Non-Farm Payrolls Test September Rate Hike Expectations, G20 Central Bank Governors Reunite, Broadcom and Dell Earnings Follow AI Trading

Who Owns the Loom: Virtuals Aims to Turn AI Agents into Tradable 'Virtual Nations'

Cryptocurrency in Retirement Funds? US Survey: Over Half of Respondents Oppose, 77% Consider It High Risk

Shin Hyun-sung: "The Won Has Gained Immunity"... Emphasizes 'Independent Judgment' Apart from U.S. Interest Rates

South Korea's Chip Leveraged ETF Trading Volume Drops to 4% Peak, Mandatory Simulation Trading Forces Retail Investors Out

Temporary Rentals in Dollars: How to Book Securely on Platforms

Tom Lee: Four Catalysts Driving ETH's Surge This Year

Tokenized Stocks Begin Trading on Base

Inflation: Projected Deceleration Below 2% and the Government Could Regain Its Floor

Coinbase’s $104M US500 trading spike hits an early reality check

The Persistence of Retail Demand: The Structural Challenge for the BCRA in the Face of Currency Coverage

ZONDACRYPTONawrocki Responds to Allegations: I Have Not Met Przemysław Kral

Major Altcoin Cleanup: 18 Cryptocurrencies Delisted from South Korean Exchanges










