Ask Finn← Discover
YOUR MONEY

A Five-Year-Old Firmware Bug Just Drained $89 Million From Bitcoin Cold Wallets

By Jamie Sullivan · Monday, August 3, 2026
Finn's Take· TL;DR
  • Five-year-old Coldcard firmware bug used software instead of hardware randomness for key generation, making seed phrases computationally guessable and vulnerable to private key theft.
  • Attackers drained $89 million across three waves in July-August, targeting long-term holders whose wallets sat dormant for years, with evolving techniques to obscure theft trails.
  • Users followed all security best practices yet still lost funds; affected individuals should immediately move Bitcoin from vulnerable Coldcard-generated addresses to patched firmware wallets.
See this from any side — with sources:
Left takeNeutralRight take

The Attack That Never Touched the Devices

This incident has become one of the largest attacks ever targeting Bitcoin self-custody through cryptographic key generation rather than malware, phishing, or exchange breaches. And what makes it especially chilling is how it worked. Researchers say a firmware flaw in certain Coldcard hardware wallets made supposedly unguessable seed phrases computationally enumerable, allowing attackers to reconstruct private keys without ever touching the devices.

The vulnerability traces back to a March 2021 firmware build affecting Coldcard Mk3 versions 4.0.1 through 4.1.9 and earlier releases. The flaw was in how those devices generated wallet seeds. Instead of routing entropy through the hardware random number generator, a bug pushed the process through a software RNG. That subtle difference — hardware randomness versus software randomness — turned thousands of supposedly secure wallets into open safes.

Three Waves, $89 Million Gone

Galaxy Research tracked the theft across three separate waves of attacks between July 30 and August 2. The firm flagged the third and most recent wave early on August 2, reporting that roughly 208 BTC was drained from 1,912 addresses between midday July 31 and the morning of August 1 UTC. The July 30 opening wave averaged close to a full coin — 1,083 bitcoin from 1,196 addresses in just 41 minutes.

Wave three sends each victim's coins to its own destination rather than the handful of shared collector addresses that made the first two easy to map, and parks them in pay-to-witness-script-hash outputs — a format that can carry multisignature or timelock conditions — instead of the plain single-key outputs used before. In other words, the attacker is learning and adapting, deliberately making the trail harder to follow with each new sweep.

The stolen coins had sat dormant for an average of 3.18 years before being swept, indicating the victims were primarily long-term holders. The incident has also highlighted a unique supply-chain risk: users who securely stored offline wallets for years remained vulnerable if the wallet was originally created with the affected firmware.

The Human Cost Behind the Numbers

Canadian fitness coach Jonathan Goodman wrote on X that 18.25 BTC — worth approximately $1.16 million — was swept from his wallets across a seven-minute window on July 29. His private keys had been stored in a physical safety deposit box and had never connected to the internet. "Perhaps the hardest part about this is that I did everything right," Goodman wrote. His story captures the gut punch of this exploit: following every rule of Bitcoin security still wasn't enough.

The exploit has reversed a common self-custody practice for many affected users, with large numbers of them moving BTC off hardware wallets and back onto centralized exchanges or freshly generated addresses. This incident complicates the self-custody narrative without fully dismantling it. What the Coldcard exploit demonstrates is that hardware wallets carry their own category of risk — specifically firmware integrity and supply-chain trust — that can be just as catastrophic.

What Coldcard Users Should Do Now

Researchers posted on August 2 that the attack is ongoing, urging anyone with single-signature funds on Coldcard-generated addresses to move them immediately. For investors holding Bitcoin in cold storage, the immediate questions are practical: which firmware version was used to generate the seed, whether an independent entropy source or BIP-39 passphrase was applied, and whether migration to a new seed on patched firmware has happened yet.

Security firms warn that more wallets could be hit because owners cannot reliably tell if their seeds were generated on vulnerable firmware, even as investigators trace the attacker through logs from a blockchain data provider. Galaxy Research warns that all vulnerable wallets will eventually be drained — making this a race against time for anyone who set up a Coldcard device between 2021 and the patch. The broader lesson for the crypto community is stark: the security of a hardware wallet is only as strong as the code that built it.

Have a question about this story?
Ask Finn — answers grounded in this article, from any viewpoint.