It did everything correctly.
Coldcard offline. Never connected to the internet.
Seed phrase stored securely.

Jonathan Goodman lost $1.6 million anyway on July 30th, 2026—attackers didn't need his device.
Just his keys. They reconstructed them from an office desk in only 41 minutes.

📌 How was it even possible: the 2021 vulnerability

In March 2021, a Coldcard firmware update introduced a silent error. Instead of using the device's built-in hardware random number generator designed to produce unpredictable seeds, the device switched to a software generator that follows patterns.

Result: the key strength went from 128 bits originally designed to just 40 real bits on the affected devices.

40 bits = brute-forceable with standard computing hardware.
Without ever touching the wallet physically.

📌 How the attack unfolded: 4 waves

Vague 1 on July 30th, 41 minutes:


1,082 BTC drained from 1,196 addresses. $70 million gone in under an hour.

The attackers generated candidate seeds, derived the addresses those seeds would produce, and checked each one against the public blockchain. This is doable with standard hardware. Because the search space was sufficiently small.

Waves 2, 3, 4 :
The following attacks targeted smaller balances with more complex transaction patterns that were harder to trace.

Final total:

1,816 BTC.

$116 million.

5,200+ addresses.
The 3rd biggest crypto hack of 2026.
Total for 2026 so far: now more than $1.2 billion across 276 incidents.

📌 What this reveals about crypto security

The attack reveals a truth that nobody wants to hear:

Offline does not mean tamper-proof.

A hardware wallet's security depends on the quality of the seed generation. If that generation is predictable, no matter whether the device ever touches the internet or not.

The question isn't "is my wallet offline?"
The question is "was my seed generated with true randomness?"

📌 Your security checklist

✅ Do you have a Coldcard?

Check whether your firmware date is after March 2021. Coinkite recommends moving your funds immediately if you generated your seed on a potentially affected device.

✅ Do you have another hardware wallet?

Verify the generation date of your seed. The Coldcard issue comes from a specific firmware, but the principle applies to any wallet whose random number generator is questionable.

✅ You don't have a hardware wallet?

Now is the right time to understand that the security of your keys > the brand of your wallet.

✅ Universal rule: Always generate your seed on a device whose firmware has been verified and audited. Never online. Never on a phone.

📌 The signal every airdrop farmer must remember

You bridge. You connect wallets to dApps.
You use MetaMask, Phantom, Rabby.

These hot wallets are exposed differently.
But the lesson is the same:

Crypto security is not a permanent state.
It's an ongoing practice.

A poorly designed firmware in 2021.
Millions lost in 2026.

Five years apart.
No visible warning.

Do you use a hardware wallet for your crypto?
And after this news, do you trust cold storage, or do you rethink your security strategy?
Tell me in the comments.

$BTC

BTC
BTC
77,248.01
-0.85%

$BNB

BNB
BNB
686.01
-0.07%

#ColdcardHack #BitcoinSecurity #HardwareWallets