$70M Vanished From "Secure" Hardware Wallets — Here's How It Happened
An attacker just pulled off one of the biggest hardware wallet exploits in Bitcoin's history — without ever touching a single device.
Over 41 minutes on July 30, someone drained 1,196 Bitcoin addresses, sweeping out 1,082.65 BTC (~$70.2M). Security firm Galaxy Research traced it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Coinkite. A 2021 integration bug had routed seed generation through a predictable software randomizer instead of the device's true hardware randomness — meaning an attacker who could work out a few technical parameters could reconstruct wallet seeds entirely offline, then just wait and sweep.
Coinkite's CEO has publicly owned the failure and pushed emergency firmware for every affected model. But here's the part that matters most for anyone holding on a Coldcard:
Updating firmware alone does NOT secure your existing funds — the compromised seed is still compromised
You need to generate a brand new recovery phrase on the fixed firmware and migrate all funds to it
Galaxy warns future attacks are still possible against any address generated the old way
This lands in an already rough year for crypto security — over $1B lost to hacks industry-wide in H1 2026
Bitcoin barely blinked — down just ~2% on the week despite this, a hawkish Fed surprise, and ETF outflows all hitting at once. That resilience says a lot about where sentiment already sits.
If you're storing serious funds on a single hardware wallet, is one device still enough — or is it time to start splitting custody?
An attacker just pulled off one of the biggest hardware wallet exploits in Bitcoin's history — without ever touching a single device.
Over 41 minutes on July 30, someone drained 1,196 Bitcoin addresses, sweeping out 1,082.65 BTC (~$70.2M). Security firm Galaxy Research traced it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Coinkite. A 2021 integration bug had routed seed generation through a predictable software randomizer instead of the device's true hardware randomness — meaning an attacker who could work out a few technical parameters could reconstruct wallet seeds entirely offline, then just wait and sweep.
Coinkite's CEO has publicly owned the failure and pushed emergency firmware for every affected model. But here's the part that matters most for anyone holding on a Coldcard:
Updating firmware alone does NOT secure your existing funds — the compromised seed is still compromised
You need to generate a brand new recovery phrase on the fixed firmware and migrate all funds to it
Galaxy warns future attacks are still possible against any address generated the old way
This lands in an already rough year for crypto security — over $1B lost to hacks industry-wide in H1 2026
Bitcoin barely blinked — down just ~2% on the week despite this, a hawkish Fed surprise, and ETF outflows all hitting at once. That resilience says a lot about where sentiment already sits.
If you're storing serious funds on a single hardware wallet, is one device still enough — or is it time to start splitting custody?