Go Back

Coldcard Wallet Bug Linked to $70 Million Bitcoin Theft

Coldcard Wallet Bug Linked to $70 Million Bitcoin Theft

Murugaverl Mahasenan

Murugaverl Mahasenan

Make Catenaa preferred on (opens in a new tab)

Catenaa, Wednesday, August 05, 2026- A security flaw affecting Coldcard hardware wallets has been linked to the theft of more than 1,000 Bitcoin, worth approximately $70 million, in one of the largest hardware wallet incidents reported this year.

Blockchain researchers at Galaxy Research said attackers drained 1,196 Bitcoin addresses, stealing 1,082.65 BTC in transactions that occurred within a 41-minute window on July 30.

The incident follows an emergency security advisory issued by Coldcard manufacturer Coinkite, which warned that certain wallet seeds generated by multiple firmware versions could leave users’ funds vulnerable.

Coinkite initially warned users of Coldcard Mk3 devices running firmware version 4.0.1, released in March 2021, that wallets created with affected software could be at risk.

The company later expanded the advisory to include selected firmware versions affecting Coldcard Mk4, Mk5 and Coldcard Q devices before releasing emergency firmware updates across all impacted models.

Chief Executive Rodolfo Novak, widely known within the Bitcoin community as NVK, publicly accepted responsibility for the software defect and apologized to customers.

He acknowledged that the company’s internal review process failed to detect the vulnerability before release.

Novak suggested the flaw may have been discovered using artificial intelligence-assisted code analysis, highlighting a rapidly emerging cybersecurity challenge for software developers.

According to Novak, AI-powered code review tools can now identify subtle vulnerabilities significantly faster than traditional manual audits, allowing attackers to locate exploitable weaknesses shortly after software becomes publicly available.

The observation reflects growing industry concerns that advances in artificial intelligence are accelerating both cyber defense and cybercrime.

Galaxy Research said blockchain analysis indicates the stolen funds followed a consistent transaction pattern pointing to a single coordinated attacker.

However, researchers cautioned that the identified blockchain movements represent only one observed attack sequence and do not necessarily capture every wallet that may remain vulnerable.

Because compromised wallet activity appears identical to legitimate owner transfers on the blockchain, identifying future attacks may prove considerably more difficult.

Coinkite has advised all affected users to immediately install the latest firmware, generate entirely new wallet seeds and transfer their Bitcoin to newly created wallets.

The company also recommends testing new wallets with small transactions before moving larger balances while retaining the original backup until transfers have been successfully completed.

The Coldcard incident demonstrates that even hardware wallets, widely regarded as one of the safest methods for storing cryptocurrency, remain vulnerable to software defects.

As digital assets continue attracting institutional and retail investors alike, firmware security, secure software development and rapid vulnerability management are becoming increasingly critical components of cryptocurrency custody.

Coldcard is one of the cryptocurrency industry’s best-known hardware wallets, designed primarily for Bitcoin self-custody. Unlike software wallets connected to the internet, hardware wallets store private keys offline to reduce exposure to cyberattacks. While hardware wallets remain among the most secure storage methods available, firmware vulnerabilities, supply chain risks and user configuration errors continue to represent potential attack vectors. The latest incident also highlights growing concern over artificial intelligence being used to identify software vulnerabilities faster than conventional security review processes.