TLDR
- A firmware bug introduced in March 2021 allowed attackers to drain over 1,778 Bitcoin from Coldcard hardware wallets
- Confirmed losses stand at $112.7 million across more than 8,600 addresses
- Galaxy Research believes attackers used unrestricted AI models to find and exploit the vulnerability
- Security researchers say US lab AI safety policies blocked them from using the same tools to defend against the attack
- No thefts were recorded from multisignature wallets; users are urged to generate new seed phrases immediately
A flaw hidden in Coldcard firmware since March 2021 allowed attackers to drain more than 1,778 Bitcoin from over 8,600 wallet addresses, making it the largest hardware wallet breach on record. At current prices, confirmed losses total $112.7 million.
⚠️UPDATE: Galaxy’s Head of Research Alex Thorn says the Coldcard attack is STILL ongoing.
The patch does not fix seeds created on the vulnerable firmware, those seeds remain permanently compromised.
Users must immediately move their funds to an entirely new wallet with a newly… https://t.co/680HKaXfut pic.twitter.com/LOLukXPvSt
— Coin Bureau (@coinbureau) August 17, 2026
The attacks began on July 30, 2026. Within 41 minutes, over 1,000 Bitcoin had been swept from more than 1,000 addresses. No attacker activity has been recorded since August 6.
The root cause was a firmware update shipped by Coinkite in version 4.0.1. That update accidentally rerouted the seed phrase generation process from a hardware random number generator to a software-based pseudorandom number generator. Software-based randomness is far more predictable, which made the generated keys easier to guess or replicate.
A developer reportedly flagged a related issue to Coinkite as early as May 2025. The vulnerability went unpatched long enough for attackers to build and deploy tools to exploit it at scale across multiple Coldcard models, including Mk2, Mk3, Mk4, Q, and Mk5.
AI Tools Played a Role on Both Sides
Galaxy Research assessed with high confidence that at least some attackers used AI models without cybersecurity restrictions to discover and exploit the flaw. The recently released open-source Kimi K3 model was named as an example of the type of system likely used.
Rob Hamilton, chief executive of Anchorwatch, said that safety policies at US frontier AI labs largely prevented security researchers from using those same tools to defend against the attack. He said this left defenders relying on the same Chinese open-source models as the attackers.
Hamilton and around 25 others, including developer James O’Beirne and Calle of the Cashu project, formed what they call the Bitcoin Red Team. The group has been scanning code repositories across the ecosystem for vulnerabilities and recommending patches.
Coinkite issued a security advisory on July 30 and released patched firmware by July 31. CEO Rodolfo Novak issued a public apology.
What Users Must Do Now
A firmware update alone does not fix the problem. Any seed phrase generated on vulnerable firmware is permanently compromised. Users must generate a completely new seed phrase on patched firmware and move all funds to new wallets.
Of the 1,778 Bitcoin confirmed stolen, 1,531 Bitcoin remains unmoved in attacker-controlled addresses. About 246 Bitcoin has been moved, with 65% going into Coinjoin mixing transactions and 35% moving on-chain through methods designed to obscure the trail.
Not one theft came from a multisignature wallet. Multisig setups require more than one key to authorize a transaction, meaning a single compromised seed is not enough to move funds.
Galaxy says it has shared attacker wallet addresses with exchanges, compliance firms, and law enforcement in hopes that funds can be frozen if they reach centralized platforms.
The theft ranks twentieth among all recorded crypto thefts, sitting below Multichain’s $130 million loss in July 2023 and above the $100 million taken from Harmony’s Horizon bridge in June 2022.







