Galaxy Research and TRM Labs confirm a five-year-old Coldcard build error allowed attackers to reconstruct private keys offline and drain $111M–$116M across more than 5,200 wallets.
- A March 2021 firmware bug collapsed effective seed entropy from 128 bits to roughly 40 bits, making offline private-key reconstruction computationally feasible.
- Attackers cleared approximately 1,082 BTC — worth $70 million at execution — from 1,196 wallets in a 41-minute opening wave on July 30, 2026.
- TRM Labs identifies at least 15 distinct threat actors; the incident is now classified the third-largest crypto hack of 2026 and the largest hardware-wallet exploit on record.
Lead
A misconfigured build flag buried in a 2021 firmware release for Coinkite's Coldcard Mk3 hardware wallet allowed attackers to silently reconstruct private keys and drain bitcoin from thousands of self-custody accounts without ever physically accessing a device. Galaxy Research confirmed losses of $111 million as of August 8, 2026; TRM Labs puts the total at $116 million spread across more than 5,200 addresses. The first theft wave, executed on July 30, moved roughly 1,082 BTC out of 1,196 wallets in 41 minutes — the largest single-session hardware-wallet drain on record.
What Happened
The flaw traces to a March 2021 firmware release affecting Coldcard Mk3 versions 4.0.1 through 4.1.9. A build configuration error caused the wallet's seed-generation routine to fall back on a software random-number generator instead of the device's dedicated hardware entropy source. The substitution reduced effective key strength from the designed 128 bits to as little as 40 bits on affected units — within reach of modern brute-force computing without physical access to the hardware.
Attackers appear to have silently pre-catalogued vulnerable public addresses before executing coordinated withdrawal bursts. Following the 41-minute opening wave on July 30, three additional theft clusters rolled out over subsequent days, expanding the total pool of drained addresses past 5,200.
Firmware Supply Chain Implications
The exploit reframes the firmware supply chain risk category for hardware security devices. Unlike supply-chain attacks that insert malicious code during manufacturing or distribution, this flaw was an internal build-process error that went undetected for more than five years across multiple firmware iterations and third-party security reviews. It required no physical tampering, no phishing, and no network access — only offline computation against weakened keys.
Market and Institutional Reaction
Bitcoin fell roughly 3% in the 24 hours following initial public disclosures on July 31, partially recovering after Coinkite released patched firmware on August 1. Spot bitcoin ETF vehicles recorded net outflows approaching $180 million in the days surrounding the announcement, as institutional clients reassessed the risk profile of self-custody relative to regulated custodians.
Self-Custody Risk in Focus
The incident directly challenges the foundational argument for hardware wallets: that offline key generation eliminates systemic attack vectors. Self-custody risk — historically framed as an operational concern around device loss or user error — now encompasses multi-year latent firmware vulnerabilities. TRM Labs attributes the coordinated scale to at least 15 distinct threat actors, several identified as opportunistic copycats who entered after initial disclosures widened awareness of the flaw.
Coinkite advised holders whose seeds were generated on affected firmware versions to migrate funds immediately to wallets initialized under patched software, unless an independent entropy source or strong BIP-39 passphrase had been applied at wallet creation.Outlook
Regulatory bodies in the United States, European Union, and United Kingdom have opened preliminary inquiries into Coinkite's disclosure timeline. The incident is expected to accelerate calls for mandatory firmware security certification and independent entropy validation standards across the hardware wallet sector. Near-term, a measurable share of retail self-custody demand is likely to shift toward institutional custody solutions and ETF-wrapped bitcoin exposure as the full scope of losses continues to be tallied.
Mentioned tickers: BTC-USD




