The Coldcard Exploit Tripled — and It's Still Running

Entropy bits actually produced versus the 128-bit standard

A week ago we wrote that cold storage didn't fail — randomness did, covering the sweep of 594 BTC from around 500 wallets. Three things have changed since, and one of them means some readers who acted on that post are still exposed.

What's different this week

The updated checklist

Why the number keeps climbing

Because a public vulnerability of this kind starts a race. The offline work — enumerating candidate seeds from a collapsed search space, deriving their addresses, checking them against the public blockchain — can be done by anyone with the write-up and enough compute. Once Block's analysis was published so users could protect themselves, it also told every other capable actor exactly where to look. That's the awful bind of responsible disclosure: silence leaves victims unwarned; publication arms the second wave. Coinkite chose to publish loudly and fast, which was right, and the multi-attacker scramble is the predictable cost.

It's also why "move your funds now, not next week" is meant literally. Every hour a vulnerable seed still holds coins is an hour it sits in a set someone is actively working through. The 72-bit figure for newer models is not comfortable either: it's far beyond casual attack, but it is a finite number in a world of well-resourced adversaries who now have a proven method and an obvious target list.

The part that should be said carefully

Institutional custodians spent this week promoting their services on the back of this, and the argument writes itself: look what happens when amateurs hold their own keys. It deserves a fair answer rather than a defensive one.

The fair answer is that this was not an amateur failure. As one security researcher put it, nobody was phished. Users who followed every piece of best-practice advice — buy a reputable air-gapped device, never connect it, never type the seed anywhere — were robbed by a defect in firmware they had no way to inspect. That is a genuine, serious argument against the naive version of "just self-custody," and pretending otherwise would be dishonest.

What it isn't is an argument for handing your coins to a custodian. This year has already produced an exchange that died with user funds inside and two more scheduling their own shutdowns. The difference is what you can do about it: this flaw came with a published advisory, an affected-version list, and a migration path — most Coldcard owners will read it and rotate without losing anything. When a custodian fails, there is no checklist. You find out when withdrawals stop, and you become a creditor.

The honest synthesis is narrower than either camp wants: self-custody is a skill, not a purchase. The defences that held here — dice entropy, a passphrase, multisig across vendors — all share one property: they refuse to let a single implementation be the sole source of your security. That principle is the actual lesson, and it costs nothing to adopt on your next wallet.

For scale, and for what it's worth as consolation: TRM Labs counted 207 separate crypto attacks in the first half of 2026 — the most in any half-year on record — totalling around $972 million, itself less than half of the $2.3 billion stolen in the same period of 2025. Bitcoin traded around $64,000 throughout this entire episode without flinching. The protocol is not what broke.

A note on risk

Nothing here is financial or security advice. This is a developing story: figures come from Galaxy Research and press reporting as of August 7, 2026, vary between sources, and Coinkite has declined to confirm any total. Affected-version details reflect Coinkite's published advisory — treat that advisory, not this article, as authoritative for your device, and check it directly before acting. Verify addresses on the device screen, send test amounts, keep seed phrases offline, and be extremely suspicious of anyone who contacts you first about your funds.

Rotate first. Swap later.

Swap wallet-to-wallet →