Loading prices…
STKR NewsSTKR News0 of 3 free this month
Bitcoin News

Coldcard Bitcoin Exploit Balloons to $88 Million as Attackers Keep Draining Wallets

A massive security failure involving Coldcard wallets has now claimed over $88 million in Bitcoin, highlighting a critical flaw in how we think about air-gapped security.

Originally on Decrypt
AB

Adrian Boysel

Contributor

Aug 2, 2026

4 min read

Photo illustration / STKR News

For years, the gold standard for protecting Bitcoin was simple: get it off the internet. We told builders and investors alike that if you wanted to be safe, you bought a hardware wallet, kept it air-gapped, and slept soundly. But the ongoing collapse of the Coldcard ecosystem is proving that the hardware itself is only as strong as the entropy it generates. We are currently watching a slow-motion train wreck that has now surpassed $88 million in drained assets.

According to the latest data from Galaxy Research, we are now into the third wave of these specific thefts. The numbers are staggering: roughly 1,367 BTC has been siphoned away across more than 4,500 individual addresses. This isn't a speculative bug or a theoretical research paper. It is an active, ongoing drain of people's life savings, and it targets the very people who thought they were being the most responsible.

The Illusion of Randomness

To understand why this is happening, you have to look at how a wallet is actually born. When you set up a device like a Coldcard, it needs to generate a private key. It does this by picking a massive, random number. In crypto terms, we call this entropy. If that randomness is flawed—meaning the number is predictable or comes from a narrow set of possibilities—an attacker can recreate your private key without ever touching your physical device.

The current exploit appears to stem from a specific firmware period where the randomness wasn't as random as advertised. Attackers are using high-compute clusters to scan the blockchain for addresses that share certain mathematical signatures. Once they find a match, they can derive the key and move the funds. The victim sees their balance hit zero, despite their hardware wallet sitting safely in a physical safe.

The Founder's Dilemma

As a founder, this is a nightmare scenario. We build products on the premise that if a user follows the rules, they are safe. Coldcard has long been the darling of the "hardcore" Bitcoin community because of its open-source ethos and lack of a battery or Bluetooth. It felt industrial. It felt secure.

But the reality is that complex code always has shadows. When you are building in the crypto space, you are essentially building a vault that is constantly being hammered by every locksmith in the world. If there is a one-in-a-million flaw in your math, the market will find it. For builders, this is a reminder that "open source" is not a magic shield. It requires constant, aggressive auditing, and even then, legacy bugs can sit dormant for years before they are weaponized.

Why the Drain is Accelerating

The reason we are seeing a "third wave" is likely due to the attackers refining their scripts. In the beginning, they probably targeted the low-hanging fruit—wallets with the most obvious mathematical weaknesses. As they've refined their compute power, they are now able to crack addresses that were slightly more complex but still flawed.

Galaxy's research indicates that the attackers are becoming more efficient at identifying these vulnerable UTXOs (Unspent Transaction Outputs). They aren't just guessing; they are systematically cleaning out a specific generation of wallets. This puts everyone who used certain versions of Coldcard firmware in a defensive position. You can't just update the software and be safe; if the original seed phrase was generated poorly, that seed is permanently compromised.

What This Means for the Industry

  • The Air-Gap Fallacy: Just because a device never touches a USB port doesn't mean it is invincible. The math is the vulnerability, not the connection.
  • Entropy Sourcing: Founders building wallet tech need to prioritize multiple sources of entropy—hardware RNGs, user input, and external dice rolls—to ensure no single point of failure.
  • Responsibility vs. Trust: We tell users "don't trust, verify," but 99% of users cannot verify the C code running on a microcontroller. The industry still relies heavily on brand trust.

The Human Cost

Behind the $88 million figure are thousands of people who did everything right. They didn't fall for a phishing link. They didn't store their keys in Evernote. They bought the expensive hardware and followed the manual. Seeing these people lose their Bitcoin is the biggest hurdle for mass adoption. If the "most secure" method fails, how do we convince the average person to step in?

From a skeptical founder's perspective, this is a moment for humility. We often get arrogant about our security protocols. We mock people for keeping coins on exchanges, yet those on Gemini or Coinbase didn't lose their shirts in this specific exploit. The trade-off between self-custody and third-party risk is getting more nuanced, not less.

The hard truth is that in the race between developers and attackers, the attackers only have to be right once. The developers have to be right forever.

Moving Forward

If you are a builder in this space, your takeaway should be about redundancy. Don't trust a single source of randomness. If you are a user, the takeaway is even simpler: if you generated a wallet on a Coldcard during the affected timeframe, you need to move those funds to a new seed generated on updated firmware or a different device entirely. Waiting for the "fourth wave" to hit is a gamble you will likely lose.

This isn't the end of hardware wallets, but it is the end of the era where we could blindly trust them as infallible. Security is a process, not a product. And right now, that process is failing thousands of people to the tune of nearly a hundred million dollars.


Read the original at Decrypt →

The Brief

Stay Updated on Cutting-Edge Tech

A six-minute morning dispatch on the markets and the technology shaping them.

Free. No spam. Unsubscribe anytime.

Write for STKR

Become a Contributor

Earn $STKR for published stories on markets, protocols, and culture.

  • Earn $STKR for every published piece
  • Editorial support from the STKR desk
  • Byline visibility across the network
  • First look at the upcoming creator program
Apply to Write

Keep reading

All stories

Comments

24 reader responses