The Coldcard exploit is still growing, and the loss estimates now disagree sharply depending on who is counting. Galaxy Research tracked roughly 1,367 BTC — about $88.6 million — across 4,585 Bitcoin addresses as of 2 August. By 4 August other researchers put the total above $130 million across some 5,200 addresses, and Fortune reported a figure near $116 million. What began as a single 41-minute sweep of 1,082 BTC from 1,196 addresses has continued through further waves, and the draining has not stopped. The cause is not a new vulnerability: it is a firmware integration error shipped in March 2021 that has been quietly poisoning wallet seeds for more than five years.

A note on the numbers: this is a live incident and every figure here is a point-in-time estimate. Trackers differ on both the BTC total and the address count because they attribute waves differently and because the BTC price moves underneath the dollar conversion. Treat any single headline number, including the ones in this article, as a floor rather than a final tally. Figures current as of 5 August 2026.
Key takeaways: losses have grown from roughly $38 million to about $88.6 million; 4,585 addresses are now affected; the root cause is a 2021 firmware build that routed seed generation to a software pseudorandom number generator instead of the hardware RNG; and every single-signature address created on an affected device is considered at risk.
What caused the Coldcard exploit
According to researchers tracking the incident, a March 2021 firmware integration error on Coinkite’s Coldcard devices caused seed generation to fall through to a deterministic software pseudorandom number generator rather than the STM32 hardware random number generator the device was designed to use. The practical effect is that the entropy behind affected seed phrases was drastically smaller than intended — small enough that private keys become guessable by brute force.
This is the worst class of hardware wallet failure, because it is silent. There is no compromised transaction, no phishing signature, no malicious approval to spot in a block explorer. A wallet generated under the flawed build looks completely normal and behaves completely normally until someone with the right search space arrives. Nothing the user did was wrong.
Why the losses keep climbing
Galaxy Research documented an initial wave that moved 1,082.65 BTC from 1,196 addresses inside a 41-minute window — a speed that indicates automated, pre-computed key derivation rather than manual targeting. Second and third waves followed on 1 August, adding a further 207.73 BTC in the third tranche alone and pushing the address count past 4,500.
The sweeps appear deliberate and programmatic. Researchers have characterised the pattern as systematic enumeration of the reduced key space, which means the attack does not stop until the space is exhausted. On current evidence, every single-signature address created on an affected device after the 2021 firmware change should be treated as compromised, whether or not it has moved yet.
What holders should check now
The guidance from researchers tracking the incident is blunt: anyone holding single-signature funds on a Coldcard should move them immediately to a wallet generated on unaffected hardware or unaffected firmware. Multi-signature configurations that combine an affected device with independently generated keys have a materially different risk profile, because compromising one key does not by itself unlock the funds.
Moving funds is only half the job. A new seed must be generated on a device whose entropy source is verified — restoring the same seed phrase onto new hardware preserves the flaw exactly. Anyone unsure which firmware their device shipped with should assume exposure rather than assume safety. Our guide to the hidden risks in cold storage wallets covers the verification steps in more detail, and we tracked the first phase of this incident in our earlier report on the Coldcard hack.
What it means
The Coldcard exploit is a supply-chain failure dressed as a security incident, and it lands on the exact product category the industry has spent a decade telling people to trust. Self-custody advice has always rested on an unexamined assumption: that the entropy inside the device is sound. This incident shows that assumption needs auditing like any other dependency, and that a build error can sit dormant for five years before anyone notices.
For institutional custodians and treasury teams, the operational lesson is about hardware diversity. Multi-signature arrangements that draw keys from a single vendor concentrate exactly the risk that materialised here. For regulated custodians in jurisdictions such as the UAE, where key-generation and operational resilience controls form part of the licensing conditions, this incident is likely to end up in the next round of supervisory questions.
Frequently asked questions
How much has the Coldcard exploit cost so far?
Galaxy Research tracked roughly 1,367 BTC, about $88.6 million, drained across approximately 4,585 Bitcoin addresses as of early August 2026, up from around $38 million when the incident was first reported. The figure has continued to rise across successive waves.
Which Coldcard wallets are affected?
Researchers link the flaw to a March 2021 firmware integration error that routed seed generation to a software pseudorandom number generator instead of the hardware RNG. Single-signature addresses created on affected devices after that firmware change are considered at risk and should be moved to a wallet generated on verified hardware.
Sources: CoinDesk, Infosecurity Magazine, The Hacker News.
This article is for information only and is not financial, investment or legal advice. Always do your own research and consult a licensed professional before making decisions.