Coldcard Hardware Wallet Exploit Drains $38M in Bitcoin
What happened: Nearly 600 bitcoin (worth approximately $38 million) were stolen from around 500 Coldcard hardware wallets in a rapid 25-minute sweep on July 30, 2026.
What happened: Nearly 600 bitcoin (worth approximately $38 million) were stolen from around 500 Coldcard hardware wallets in a rapid 25-minute sweep on July 30, 2026. The root cause was a firmware bug introduced in March 2021, which led to the use of weak, predictable entropy for private key generation. The flaw affected Coldcard Mk2 and Mk3 devices running firmware versions 4.0.0 to 5.0.3, and potentially Mk4, Mk5, and Q models. Coinkite, Coldcard's maker, released patched firmware but warned users that affected wallets must migrate funds, as patches cannot secure already-generated seeds. The exploit has reignited debate over the risks of self-custody, with some industry voices suggesting it may push retail investors toward regulated custodians and spot bitcoin ETFs.
Why it matters: This is one of the largest hardware wallet breaches to date, undermining confidence in self-custody solutions that have long been promoted as the gold standard for crypto security. The exploit's technical nature—potentially discovered using AI tools—highlights the growing sophistication of attackers and the challenges of securing open-source hardware. While ETF migration is being discussed as a possible consequence, no empirical data yet shows a surge in ETF inflows linked directly to the incident. The event raises critical questions about the trade-offs between self-sovereignty and institutional custody as digital asset adoption broadens.
Source: CoinDesk