TLDR
- A firmware flaw in Coldcard hardware wallets has led to losses of over $130 million in Bitcoin across multiple attack waves
- Bitcoin active addresses hit 980,000 per day, the highest since December 2024, driven by security concerns not market optimism
- At least 15 different attackers exploited the vulnerability, with a fourth wave suspected
- Hackers sent 64 Bitcoin and 200 Ether to crypto mixing services Wasabi and Tornado Cash to obscure stolen funds
- The Coldcard exploit is now the third-largest crypto hack of 2026
A firmware flaw in Coldcard hardware wallets has triggered one of the biggest Bitcoin security events of 2026, with losses now estimated at over $130 million.
The #Coldcard hacker, who stole 2,055 $BTC($130M), is active again.
An hour ago, the hacker transferred 30.185 $BTC($1.94M) to a new wallet.https://t.co/Edirjbd2G0https://t.co/ksoTpGxx3g pic.twitter.com/VTL5UB9xgH
— Lookonchain (@lookonchain) August 7, 2026
The vulnerability dates back to March 2021, when a firmware bug weakened the randomness of seed generation on affected devices. This cut key strength from 128 bits to just 40 bits, making wallets brute-forceable without any physical access.
Galaxy Digital confirmed at least three waves of attacks, draining funds from 7,300 victim wallets. A suspected fourth wave could push total losses even higher.
Bitcoin On-Chain Activity Spikes
Blockchain analytics firm Glassnode reported that Bitcoin active addresses surged to around 980,000 per day following the exploit. That is the highest level since December 2024.
Glassnode was clear that the spike was not driven by market enthusiasm. The firm described it as “an operational security response, not a change in market conviction.”
Dormant Bitcoin worth nearly 200 times the value of the initially stolen funds moved across the network, suggesting many holders were moving assets out of caution.
The July 31 theft of 594 Bitcoin, worth around $38 million at the time, was the event that triggered the wider on-chain response. Galaxy Research later confirmed losses had exceeded 1,596 Bitcoin, worth more than $100 million.
Hackers Route Funds Through Mixers
Blockchain security firm CertiK tracked the movement of stolen funds. Around 64 Bitcoin, worth $4.17 million, was sent to Wasabi, a Bitcoin mixing protocol. Separately, 200 Ether worth around $380,000 was sent to Tornado Cash.
Our alert system detected two 200 ETH transactions sent to Tornado Cash linked to the ongoing @COLDCARDwallet attack.
The funds were bridged from BTC to ETH address 0x41B7529a411EeA979a8d468bdEBd36b0ad703268 via THORChain before being sent to Tornado Cash. pic.twitter.com/JLazHWIEvo
— CertiK Alert (@CertiKAlert) August 5, 2026
CertiK suggested some of these transfers may have come from copycat attackers. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK spokesperson said.
TRM Labs confirmed that most stolen funds are still sitting in a small number of attacker-controlled wallets. The differences in how each attack wave was constructed point to at least 15 separate attackers.
Dragonfly managing partner Haseeb Qureshi noted that some AI models reportedly rediscovered the underlying vulnerability in less than 20 minutes. He suggested roughly two dollars of AI-based hardening could have prevented the exploit.
Security experts say updating firmware alone is not enough for affected users. Anyone who created a wallet on a compromised device is advised to generate a new wallet and move their funds immediately.
The Coldcard exploit now ranks as the third-largest crypto hack of 2026 so far.







