$89M Bitcoin heist from Coldcard wallets: 1,200 addresses drained in record time
Over $89 million in Bitcoin was stolen from 1,200+ Coldcard hardware wallets after a firmware flaw made seed phrases predictable. The attack blitz on July 30, 2026, raises urgent questions about the safety of cold storage and may trigger a sell-off among spooked self-custody users.
Key Takeaways
- Over $89 million in Bitcoin was stolen from 1,200+ Coldcard hardware wallets after a firmware flaw made seed phrases predictable.
- The attack blitz on July 30, 2026, raises urgent questions about the safety of cold storage and may trigger a sell-off among spooked self-custody users.
Mentioned
Key Intelligence
Key Facts
- 1Attackers drained over 1,000 BTC (initially valued at ~$70M) from 1,196 wallets in just 41 minutes on July 30, 2026.
- 2Galaxy Research identified two additional waves of theft, raising the total estimated loss to nearly $89 million across 1,200+ addresses.
- 3A coding mistake in certain Coldcard firmware versions weakened the entropy of recovery phrases, making them predictable to attackers.
- 4Coinkite released a firmware update to fix the bug for new wallets, but existing wallets created with vulnerable firmware remain at risk unless new seed phrases are generated and funds transferred.
- 5Block’s Bitcoin Engineering and Security team issued an urgent advisory, warning that attacks are still ongoing.
Bitcoin
BTC- Market Cap
- $1.87T
- 24h Change
- -1.25%
- Rank
- #1
Analysis
For Bitcoin holders, the Coldcard disaster is a gut punch. Many chose hardware wallets precisely to avoid the kind of hot-wallet hacks that plague exchanges, only to learn that their ‘unhackable’ device had a fatal flaw in its seed generation. With $89 million gone in 41 minutes, trust in cold storage—once the bedrock of self-sovereign Bitcoin—has been deeply shaken, and the price impact could be immediate.
A catastrophic security breach has rocked the cryptocurrency world, with attackers exploiting a flaw in the popular Coldcard hardware wallet to siphon an estimated $89 million in Bitcoin from over 1,200 addresses. The heist, first reported by Forbes and analyzed by Galaxy Research, unfolded with alarming speed on July 30, 2026—draining more than 1,000 BTC from 1,196 wallets in a mere 41 minutes. Subsequent waves of suspicious activity identified by Galaxy pushed total losses to nearly $89 million, making this one of the largest single-day thefts traceable to a hardware wallet vulnerability.
The $89 million loss, while relatively small in the context of Bitcoin’s $1.2 trillion market cap, represents a profound failure of trust.
Coldcard, manufactured by Canadian firm Coinkite, is widely regarded as a bastion of offline security, designed to isolate private keys from internet-connected threats. The breach shatters that perception. According to a security advisory from Block’s Bitcoin Engineering and Security team, a coding error in certain Coldcard firmware versions fundamentally weakened the randomness—or entropy—of the recovery phrases generated during wallet setup. These 12- or 24-word seed phrases are the keys to the kingdom; if an attacker can predict or brute-force them, they can reconstruct a wallet’s entire keychain and steal funds without ever touching the physical device. The bug effectively made some recovery phrases predictable enough for sophisticated adversaries to systematically drain accounts.
The speed and precision of the July 30 attack—1,196 wallets in 41 minutes—point to a highly automated operation. Attackers likely scanned the blockchain for addresses linked to vulnerable wallets, computed the weak seed phrases, and swept the BTC in rapid succession. This was not a smash-and-grab but a surgical execution, indicating deep knowledge of the flaw and possibly preparatory infrastructure. Galaxy’s blockchain analysis confirmed that while the initial wave grabbed headlines, two additional waves compounded the damage, underscoring that the threat is ongoing. Block explicitly warned that attacks are still happening, even as forensic details remain under investigation.
Coinkite has released a firmware update to fix the entropy bug for newly created wallets, but it issued a crucial caveat: installing the update does not retroactively secure wallets generated with the vulnerable firmware. Users who created wallets on affected versions must generate entirely new recovery phrases and transfer their funds to new addresses—a painful and potentially costly process that many might overlook. This gap leaves thousands of existing wallets exposed indefinitely, especially as word of the vulnerability spreads among malicious actors.
The implications stretch far beyond Coldcard’s user base. Hardware wallets have long been marketed as the gold standard of crypto self-custody, immune to online hacks. This incident eviscerates that assumption, revealing that even air-gapped devices depend on secure software implementation. A single coding mistake in entropy generation can cascade into mass theft. The advisory from Block—a company founded by Jack Dorsey with deep ties to Bitcoin—lends extraordinary credibility to the warning, signaling that the industry must urgently reexamine how hardware wallets are engineered and audited.
What to Watch
Market confidence in self-custody solutions will likely waver. The $89 million loss, while relatively small in the context of Bitcoin’s $1.2 trillion market cap, represents a profound failure of trust. Investors who flocked to hardware wallets after exchange collapses like FTX now face the reality that no storage method is foolproof. Coinkite, a smaller player compared to Ledger or Trezor, may struggle to recover its reputation, especially without a clear path to compensate victims. Regulatory scrutiny is almost certain to intensify, potentially driving new standards for wallet certifi
Looking ahead, the industry must prioritize transparent security audits and robust random-number generation testing. This breach serves as a stark reminder that the human element—coding errors—remains the weakest link even in cold storage. Users should audit their wallet generation history and migrate assets immediately, but the broader lesson is clear: trust, once lost, is hard to restore in the Wild West of digital assets.
Timeline
Timeline
Initial mass theft
Attackers drain over 1,000 BTC from 1,196 wallets in 41 minutes, initially valued at approximately $70 million.
Additional theft waves detected
Galaxy Research identifies two further suspicious transaction sequences, bringing total estimated losses to nearly $89 million.
Public disclosure and advisory
Block’s Bitcoin Engineering and Security team releases a security advisory revealing the entropy-generating coding flaw in Coldcard. Coinkite issues a firmware update that fixes the vulnerability for new wallets but warns that existing wallets remain vulnerable.
Sources
Sources
Based on 3 source articles- fox13seattle.comColdcard wallet attack drains up to $89M in Bitcoin from 1 , 200+ addressesAug 3, 2026
- fox5atlanta.comColdcard wallet attack drains up to $89M in Bitcoin from 1 , 200+ addressesAug 4, 2026
- fox13news.comColdcard wallet attack drains up to $89M in Bitcoin from 1 , 200+ addressesAug 4, 2026
Cite This Page
"$89M Bitcoin heist from Coldcard wallets: 1,200 addresses drained in record time." Crypto Intelligence Brief, August 4, 2026. https://getcryptobrief.com/story/coldcard-89m-bitcoin-heist-crypto
How we covered this story
Every story in our crypto coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the crypto space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled crypto-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |