A software flaw in Coldcard hardware wallets exposed an estimated $130 million in bitcoin to theft, security researchers reported in early August 2026 [1, 2, 3, 4]. The vulnerability stemmed from a weakness in the wallet firmware’s random number generation, which made users’ seed phrases predictable and guessable by hackers [2, 3, 5].
The backdoor existed in some firmware versions released since March 2021 and went unnoticed in Coldcard’s open-source code for over five years [3, 5]. Galaxy Research tracked multiple waves of theft totaling about 1,596 bitcoins stolen from more than 7,300 wallets globally by August 2026 [3, 4]. Victim wallets included addresses owned by federal investigators, compliance firms, and cybersecurity researchers [3].
At least a dozen hacker groups exploited the flaw to pillage these funds, according to blockchain analysis [2]. In one notable market reaction, roughly 728,000 bitcoin wallets moved their funds on August 5 alone, as users rushed to secure their assets in safer storage solutions [1].
Coinkite, the company behind Coldcard, issued emergency firmware updates on July 31, 2026, urging users to generate new wallets and transfer their holdings promptly [5, 4]. Despite using AI tools in security auditing, the critical flaw was not detected earlier. As Charles Guillemet, CTO of Ledger, said, “The security model of hardware wallets relies heavily on random number generation” and AI both increases vulnerability discovery speed and forces defenders to respond quickly [1, 5, 4].
Users have expressed frustration over the incident. Coldcard user Jonathan Goodman said, “Perhaps the hardest part about this is that I did everything right. I never shared my seed phrase with anybody. My devices never touched the internet” [2]. Nikhil Raghuveera, CEO of Predicate, noted the breach “shakes trust in the whole model” of self-custody digital assets [1].
Dragonfly partner Haseeb Qureshi added, “We have no choice but to adapt” to such security challenges [5]. Coinkite’s patch release marks the immediate next step for affected users to secure their assets from ongoing attacks [5, 4].