> ## Content Index
> Fetch the complete content index at: https://www.aboutdefi.asia/llms.txt
> Use this file to discover other available public pages before exploring further.

# Coldcard Hack : $100M+ gone 💸
- URL: https://www.aboutdefi.asia/coldcard-hack-100m-gone/
- Published: 2026-08-08T15:10:32.000Z
- Updated: 2026-08-10T15:51:01.000Z
- Author: Kendrick
- Tags: Briefs

The safest place to keep Bitcoin just got emptied out, and nobody had to touch a single device to do it. A five-year-old bug in the Coldcard, one of the most trusted hardware wallets on the market. Since July 30, attackers walked off with more than $100 million. 

## If you only read this

- **A top-tier hardware wallet generated keys that weren't actually random.** Attackers have drained roughly $116 million, climbing toward $130M by some counts, from thousands of wallets since July 30, without ever touching a device.
- **Bitcoin didn't break. One vendor's key generation did.** But it puts a crack in the whole "just self-custody and you're safe" story.
- **Act today if it's you or someone you know:** a Coldcard Mk2 or Mk3 seed made on the affected firmware, with no passphrase and no dice rolls, is compromised even after you update. The coins have to move to a fresh seed.

---

## What actually happened

**Takeaway: a device whose entire job is to invent an unguessable secret invented a guessable one.**

Your hardware wallet has one core job: create a secret so random that guessing it is hopeless. Picture a safe combination with one chance in a billion billion. In March 2021, the Coldcard, made by the well-regarded Canadian firm Coinkite, shipped a bug that quietly swapped its dedicated hardware randomness for weak software randomness. Key strength collapsed from 128 bits to about 40, the difference between "longer than the age of the universe to crack" and "an afternoon on a decent computer." So the attackers didn't steal devices or phish anyone. They just guessed, offline. And the flaw sat undiscovered for five years while people generated seeds and assumed their coins were in a vault. The door had been unlocked since 2021.

---

## The damage, and an honest word on the number

**Takeaway: treat it as "$116M and climbing," not a final figure.**

![](https://storage.ghost.io/c/e0/36/e036a895-ee73-41a8-93e1-b14e4539361b/content/images/2026/08/coldcard-timeline.png)

The first wave, on July 30, took about 594 BTC (roughly $38M) from around 500 wallets in 25 minutes, and it went straight for the richest, most dormant wallets. More waves followed. Forensics firm TRM Labs puts the running total near 1,816 BTC, about $116 million, across more than 5,000 addresses; other trackers cite up to $130 million as they trace further, so treat the figure as unfinished. At least a dozen different attackers appear to be involved, none yet identified. Coinkite shipped patched firmware within about two days, but here is the sting: updating protects new seeds, not the one you already made. It is now the third-largest crypto hack of 2026, a year already past $1.2 billion in thefts across 276 incidents.

---

## Are you exposed?

![](https://storage.ghost.io/c/e0/36/e036a895-ee73-41a8-93e1-b14e4539361b/content/images/2026/08/coldcard-exposure-3.png)

**Three questions settle it:**

- **Model.** A Coldcard Mk2 or Mk3 is the danger zone (Mk3 firmware 4.0.1 through 4.1.9 is worst). Newer Mk4, Mk5 and Q seeds were weaker than intended too.
- **Setup.** Was the seed generated on the device with no extra passphrase and no dice rolls? Either of those two habits likely saved you.
- **Size.** The attacker chased balances above \~0.15 BTC first and worked down. Small, untouched wallets aren't safe, just not reached yet.

**For you:** if the answers are Mk3, no passphrase, and any real balance, move the coins to a brand-new seed on updated firmware today. Then message anyone you know who self-custodies and ask them the same three questions. The people most at risk are the least likely to be watching.

---

## This isn't a Bitcoin problem, and that's the point

**Takeaway: self-custody moved the risk. It didn't remove it.**

Here is where I split the scary headline from the fundamentals, because they point in opposite directions. Bitcoin's cryptography is untouched, the network wasn't breached, and this was one company's mistake in how it rolled the dice. The market agreed: Bitcoin barely moved on the news. So the sky isn't falling.

But don't get too comfortable. Coinkite is not a fly-by-night brand, it's one of the most respected names in the category, and its gold-standard product carried a silent flaw for five years. As TRM's Ari Redbord put it, "self-custody moves the risk, it does not remove it." And this keeps happening for the same reason every time: a randomness source everyone assumed was strong turned out to be weak. Same failure sank the Wintermute vanity-address hack in 2022 and the Milk Sad disclosure in 2023\. Different code, different year, identical hole. The lesson isn't "don't self-custody." It's trust the principle, verify the implementation. Cold storage is still right for most long-term holders. Cold just doesn't mean infallible.

---

## The AI twist

**Takeaway: AI is now both the cheapest fix and, maybe, the finder.**

Because Coldcard's code is open source, Coinkite says it has to assume someone used AI to comb old firmware and find the flaw. Read that as their speculation, not proven fact. But the direction is real. Dragonfly's Haseeb Qureshi noted that roughly "$2 of AI hardening" could have caught this, and that some AI models reportedly rediscovered the bug in under 20 minutes. Both halves of that matter. Defenders can now cheaply re-audit years of "battle-tested" code. So can attackers. The comfortable assumption that old open-source code has already been checked by enough eyes is exactly the thing that just got more dangerous.

---

## The Asia read

**Takeaway: Western coverage says "be careful with your wallet." For Asia, this is the case for the custody rules the region is writing this year.**

Most coverage frames this as a retail warning: mind your hardware wallet. That misses what matters for anyone operating institutionally out here. Hong Kong and Singapore are, right now, writing the custody rulebooks that will govern how funds, exchanges and banks hold client crypto, with Hong Kong's custodian licensing regime due this year. And the controls serious institutional custody already uses are the exact ones that would have caught or contained this: keys generated independently and verifiably, split across multiple parties so no single vendor is a single point of failure, not one device quietly trusted to roll the dice alone.

The lesson the region needs to internalise: "we use a hardware wallet" is not a custody standard. "Whose keys, generated how, verified by whom, recoverable how" is. As Asia codifies institutional custody, key-generation provenance stops being a footnote and becomes a licensing-grade question.

**For you:** if you allocate to or run a platform, fund or custodian in the region, put firmware and key-generation provenance on your due-diligence list and in your counterparty questions. A trusted brand name is not an answer.

---

## Our read

Don't confuse a calm Bitcoin price for an all-clear. Here's my actual read.

This hack doesn't dent Bitcoin, but it taxes something scarcer in a bear market: trust. Capital choosing between AI, collectibles and crypto does not need another reason to stay away, and every "the safe thing wasn't safe" headline hands it one. That cost lands on everyone in the space, not just the victims.

And it's about to get faster. The people who drained Coldcard didn't need a lab or a nation-state budget. They needed cheap AI and old code nobody had re-checked, and that combination is compounding, not fading. AI tooling changes week to week, and right now it's pointed at every "battle-tested" codebase and custody setup that has sat untouched for years, probing around the clock for the price of a coffee. Sit with the math: most firms set their security up once, at a fixed point in time. The people trying to break it upgrade their tools every single day.

That's why the equilibrium favours the attackers, and why it only flips for the firms that refuse to treat security as a one-time setup. The ones that survive this cycle won't be the loudest. They'll be the ones who kept pace: who know what the leading institutional desks are actually using to generate keys, hold assets and verify their own assumptions, and who upgraded before an incident made the decision for them. Everyone else is just a wallet that hasn't been reached yet.

So here's the only question that matters now. Not "do you have a hardware wallet." It's "is your security keeping up with the people trying to beat it." If the honest answer is "I'm not sure," that is the answer, and it's the one worth fixing this week.

**PS.** Most of my week is spent inside exactly these conversations, with exchanges, funds, custodians and banks across Asia, on what an institution-grade setup actually looks like and which tools the best desks quietly rely on to stay off lists like this one. If you're building that foundation, or you suspect yours is running on an assumption nobody has checked, come talk to me. It's the conversation I never get tired of having.

---

*Market intelligence for independent decisions, not financial advice.*

![](https://storage.ghost.io/c/e0/36/e036a895-ee73-41a8-93e1-b14e4539361b/content/images/2026/08/coldcard-exposure.png)