The Coldcard Exploit Tripled — and It's Still Running

A week ago we wrote that cold storage didn't fail — randomness did, covering the sweep of 594 BTC from around 500 wallets. Three things have changed since, and one of them means some readers who acted on that post are still exposed.
What's different this week
- The total roughly tripled. Galaxy Research tracked about 1,816 BTC — some $116 million — taken from more than 5,200 addresses across at least four waves by August 4; TechCrunch, citing the same firm, reported roughly $130 million. The largest single sweep moved 1,082 BTC from 1,196 wallets in 41 minutes. Coinkite says it cannot confirm any of these figures and will not estimate its own.
- It is not over. Coldcard confirmed on August 4 that the threat is ongoing, and Galaxy reports that multiple groups — at least a dozen distinct actors by its count — are now working the same flaw. This is no longer one attacker with a head start.
- The newer models are no longer in the clear. This is the correction that matters. Our first report relayed Coinkite's early analysis that Mk4, Mk5 and Q were unaffected. Coinkite's completed technical review revised that: those models mix in randomness from a separate security chip, which raises the effective strength to roughly 72 bits — better than the ~40 bits on affected Mk2 and Mk3 devices, and still far below the 128-bit standard a seed is supposed to carry.
The updated checklist
- Mk3 (and Mk2) — if the seed was generated on firmware 4.0.1 or later, treat it as compromised. Move funds to a wallet created on patched firmware, now.
- Mk4, Mk5, Q — if you are on firmware below 5.6.0 (or 1.5.0Q for the Q), update the firmware, create a new wallet, and move your coins to it. Updating alone is not sufficient.
- Updating firmware does not repair an existing seed. The weakness lives in the seed itself. A weak seed restored onto patched firmware, or imported into any other wallet, stays weak forever. You need a new seed and a new address.
- You are likely fine if you used the dice option — physically rolling dice at least 50 times during setup — or a BIP-39 passphrase (which is not the device PIN, and doesn't count if you've typed it into a phone or website). Multisig across different manufacturers also holds.
- Move deliberately, not frantically. Verify the new receive address on the device screen, send a small test amount first, confirm it arrives, then move the rest. Wind-downs and exploits are peak season for fake wallets and "recovery" scams — nobody legitimate will DM you about this, and Coinkite's own advisory is the authoritative source.
Why the number keeps climbing
Because a public vulnerability of this kind starts a race. The offline work — enumerating candidate seeds from a collapsed search space, deriving their addresses, checking them against the public blockchain — can be done by anyone with the write-up and enough compute. Once Block's analysis was published so users could protect themselves, it also told every other capable actor exactly where to look. That's the awful bind of responsible disclosure: silence leaves victims unwarned; publication arms the second wave. Coinkite chose to publish loudly and fast, which was right, and the multi-attacker scramble is the predictable cost.
It's also why "move your funds now, not next week" is meant literally. Every hour a vulnerable seed still holds coins is an hour it sits in a set someone is actively working through. The 72-bit figure for newer models is not comfortable either: it's far beyond casual attack, but it is a finite number in a world of well-resourced adversaries who now have a proven method and an obvious target list.
The part that should be said carefully
Institutional custodians spent this week promoting their services on the back of this, and the argument writes itself: look what happens when amateurs hold their own keys. It deserves a fair answer rather than a defensive one.
The fair answer is that this was not an amateur failure. As one security researcher put it, nobody was phished. Users who followed every piece of best-practice advice — buy a reputable air-gapped device, never connect it, never type the seed anywhere — were robbed by a defect in firmware they had no way to inspect. That is a genuine, serious argument against the naive version of "just self-custody," and pretending otherwise would be dishonest.
What it isn't is an argument for handing your coins to a custodian. This year has already produced an exchange that died with user funds inside and two more scheduling their own shutdowns. The difference is what you can do about it: this flaw came with a published advisory, an affected-version list, and a migration path — most Coldcard owners will read it and rotate without losing anything. When a custodian fails, there is no checklist. You find out when withdrawals stop, and you become a creditor.
The honest synthesis is narrower than either camp wants: self-custody is a skill, not a purchase. The defences that held here — dice entropy, a passphrase, multisig across vendors — all share one property: they refuse to let a single implementation be the sole source of your security. That principle is the actual lesson, and it costs nothing to adopt on your next wallet.
For scale, and for what it's worth as consolation: TRM Labs counted 207 separate crypto attacks in the first half of 2026 — the most in any half-year on record — totalling around $972 million, itself less than half of the $2.3 billion stolen in the same period of 2025. Bitcoin traded around $64,000 throughout this entire episode without flinching. The protocol is not what broke.
A note on risk
Nothing here is financial or security advice. This is a developing story: figures come from Galaxy Research and press reporting as of August 7, 2026, vary between sources, and Coinkite has declined to confirm any total. Affected-version details reflect Coinkite's published advisory — treat that advisory, not this article, as authoritative for your device, and check it directly before acting. Verify addresses on the device screen, send test amounts, keep seed phrases offline, and be extremely suspicious of anyone who contacts you first about your funds.
Rotate first. Swap later.
Swap wallet-to-wallet →