In just 41 minutes, an attacker drained 1,196 Coldcard hardware wallets of 1,082.65 bitcoin—roughly $70 million—without ever physically touching the victims’ devices. The July 30, 2026 attack exploits a firmware flaw that effectively neutralizes the entropy meant to safeguard private keys.
🔑 Key takeaways
- 1,082.65 BTC (≈$70M) stolen between 01:10 and 01:51 UTC on July 30, 2026
- 1,196 Coldcard wallets affected according to Galaxy Research, more than double early estimates
- Flaw in the random number generator bypassed the hardware RNG in favor of a software fallback
- Coinkite urges users to update to firmware 5.6.0+ (Mk4/Q/Mk5) and 4.2.0+ (Mk3)
- The attacker used a paid blockchain service account, allowing Block to trace the activity
A timed attack with no physical contact
On July 30, 2026, between 01:10 and 01:51 UTC, an unidentified operator siphoned funds from nearly 1,200 Coldcard hardware wallets in just 41 minutes. According to Galaxy Research’s comprehensive report, six Bitcoin blocks were used to broadcast the transactions, separated by three empty blocks—a pattern suggesting batched payouts rather than continuous transfers. In total, 1,082.65 BTC were moved and consolidated onto four destination addresses that have not been touched since the attack.
The final amount, valued at roughly $70 million at the time, is nearly double the $38 million initially reported by some outlets. Galaxy Research attributes the gap to early reports capturing only one of the destination addresses: bc1qnk, identified by analytics firm Lookonchain, which alone received 594 BTC (about $38.5 million). The remainder came from the three other addresses that flew under the radar during the first hours of investigation.
The victim count was also revised upward. While several sources initially cited 500 drained wallets, Galaxy Research counted 1,196. Of these, 1,183 used the native segwit format, seven used an older P2PKH standard, and six used an even older P2SH format. This diversity of address formats within a single attack points to a systematic enumeration of vulnerable seeds, rather than targeted victim selection.

A flaw in the random number generator
The method hinges on a vulnerability in the Coldcard firmware. Under normal conditions, these devices generate private keys from a 256-bit random number so vast that no current computer could enumerate it in any reasonable timeframe. But a configuration error in the firmware caused the hardware random number generator to be bypassed entirely in favor of a basic software substitute.
That fallback relied on two elements an attacker can easily reproduce: the chip’s serial number (factory-fixed metadata) and the clock register values at the moment of seed generation. An attacker could measure those same clock values on their own device at the same moment and obtain the same result as the victim.
| Model | Effective entropy | Risk level | Required firmware |
|---|---|---|---|
| Mk2 | Deterministic | Total | Discontinued |
| Mk3 | Deterministic | Total | 4.2.0+ |
| Mk4 | ≈ 4 billion | High | 5.6.0+ |
| Q | ≈ 4 billion | High | 5.6.0+ |
| Mk5 | ≈ 4 billion | High | 5.6.0+ |
The entropy consequences are severe. On Mk2 and Mk3 models, key generation became fully deterministic: the same serial number paired with the same clock state always produces the same seed. On newer models (Mk4, Q, Mk5), Galaxy Research estimates the search space at roughly 4 billion possibilities. A figure that sounds large to a human, but one a modern computer can sweep through in a few hours with a well-written script.
The full process took place entirely on the attacker’s machine: candidate seed generation, derivation of the corresponding addresses, then verification against the public blockchain. The victim’s device was never involved—it could have been sitting powered off in a safe on another continent, and the outcome would have been identical.
The attacker’s fatal mistake
Despite the technical sophistication of the attack, the operator made a slip that enabled identification. Clay Garrett of Block (formerly Square) explained on X that investigators noticed an unusual pattern in the pre-drain scans. The attacker had used a paid account with a well-known blockchain service provider to query source addresses while searching for vulnerable seeds.
« During our investigation into yesterday’s Coldcard drain, we identified an unusual pattern in the scans. This pattern led us to a hypothesis that has since been confirmed: the operator used a paid account with a known blockchain service provider to query source addresses during the scans. »
Clay Garrett, Block
The provider’s internal logs matched the suspect workflow with, in Garrett’s words, « extraordinary specificity »—including the number, timing, and sequence of requests. Block forwarded the full set of information to the relevant authorities. The detail is striking: an attacker methodical enough to reproduce firmware states should not have left such a trace through a third-party service.
Coinkite’s response and market fallout
Coinkite, the Coldcard manufacturer, issued a security advisory asking all users to update their devices: Mk4 and Mk5 to firmware 5.6.0 or higher, Q to the same version, and Mk3 to 4.2.0 or newer. The message was unambiguous: « Do not create a new passphrase on any of these models until the update is installed. » Coinkite also stated that Mk4, Q, and Mk5 were not affected by the initial flaw—though the joint Galaxy Research and Block report describes vulnerabilities on those models as well.
The firm noted that an affected Mk3 seed, combined with a BIP-39 passphrase (an extra password layered on the 12- or 24-word seed), would have neutralized the risk. It recommends affected users migrate their funds to a new wallet while urging calm and methodical action rather than panic.
In the markets, on July 31, bitcoin dropped 2.67% to $63,054.01 while Ethereum lost 2.84% to $1,864.99, according to Binance data. Coinbase shares plunged after the company reported quarterly results below expectations, marking a third consecutive red quarter. Strategy (formerly MicroStrategy) also posted a loss tied to the depreciation of its bitcoin holdings.
Despite the sell-off, US spot bitcoin ETFs recorded $233.1 million in net inflows on July 30—the largest volume since July 6, per CoinGlass data. For Rania Gule, analyst at XS.com, the signal shows that « institutional investors have not abandoned the market, » though a more robust ETF performance will be required to lift bitcoin out of its current trading range.
A blow to self-custody culture
Beyond the numbers, the incident has dented confidence across part of the community. On Reddit, one user wrote that the episode « killed the faith of many bitcoiners, » comparing it to the collapse of FTX in 2022. One investor reported losing 0.79 BTC—around $51,000—from a Coldcard. Jameson Lopp, co-founder of self-custody firm Casa, said he had been contacted by multiple affected users.
Maurício Magaldi, founder of the BlockDrops podcast, offered a more structural warning: « The risk of being your own bank, as crypto enthusiasts advocate, is the same as being a bank. Self-sovereignty still requires deep technical expertise, and the trade-off between user-friendly experience and security remains unresolved. »
« There is no test that can be run on one’s own wallet to reveal whether the seed falls within the reproducible range. »
Galaxy Research, incident report
Galaxy Research warned of likely new waves of theft if Coldcard owners fail to migrate their funds. Crucially, the firm stressed that there is no test a user can run on their own device to determine whether their seed falls within the reproducible range. That opacity turns every non-migrated Coldcard into a potential time bomb.
Conclusion
Founded in 2017 by Peter Gray and Rodolfo Novak, Coldcard had become one of the go-to devices for Bitcoiners prioritizing maximum security. The July 30, 2026 attack shows that no hardware wallet is infallible, and that a firmware flaw alone can turn a digital vault into a sieve—without the attacker ever needing to touch the device itself.
For Coldcard holders, the priority is clear: update the firmware, migrate funds to a new seed generated on a patched device, and consider adding a BIP-39 passphrase as an extra layer of protection. Longer term, the episode raises a foundational question about the resilience of the self-custody model: the promise of full sovereignty only holds if users possess the technical ability to verify the integrity of their own tools, and not just trust the manufacturer’s brand.
Sources
This article is published for informational and educational purposes only. It does not constitute investment advice. Do your own research (DYOR) before making any decision.

