Skip to content

Cryptoassets are highly volatile and largely unregulated. No consumer protection. Tax on profits may apply. Cryptoassets are highly volatile and largely unregulated. No consumer protection. Tax on profits may apply.

Coldcard Hardware Wallet Hack Drains $89m: What It Means for Crypto Self-Custody

A firmware flaw in Coldcard hardware wallets, made by Canadian manufacturer Coinkite, has been exploited to drain roughly 1,367 BTC - worth close to $89 million - from thousands of addresses since 30 July 2026. The incident has unsettled the crypto market because it targeted "cold storage," long considered the safest way to hold bitcoin. Here's what actually happened, why security researchers say it isn't a flaw in bitcoin itself, and what UK crypto holders can take from it.

Bitcoin Source: Bloomberg

Written by

IG Editorial Team

IG Editorial Team

Editorial Team

Publication date

Key takeaway

  • A firmware bug in Coldcard hardware wallets allowed attackers to reconstruct wallet seed phrases and steal funds, without ever physically accessing the device.
  • Total losses across multiple attack waves beginning 30 July 2026 reached roughly 1,367 BTC (about $89 million) from 4,585 addresses, according to Galaxy Research.
  • The root cause was weak random-number generation dating to a March 2021 firmware build - not a flaw in the Bitcoin protocol itself.
  • Bitcoin's social sentiment ratio fell to some of its most negative readings on record, even though the dollar losses are small next to events like the FTX collapse.
  • Coinkite has released patched firmware; affected users are advised to migrate funds to newly generated, unaffected seeds.

What happened in the Coldcard hardware wallet exploit

Coinkite Inc., maker of the Coldcard hardware wallet, notified users in late July 2026 that a security flaw in older firmware had compromised some wallets. Attackers exploited the flaw across several distinct waves: roughly 594 BTC (about $38 million) was drained in the first wave on 30 July, rising to about 1,082 BTC by 1 August, and reaching approximately 1,367 BTC (around $89 million) from 4,585 addresses by 2–3 August, according to on-chain analysis from Galaxy Research. A further wave was reported live on 3 August.

How the firmware flaw worked

The issue traces back to a March 2021 firmware build affecting certain Coldcard Mk2 and Mk3 versions. Instead of routing seed-phrase generation through the device's dedicated hardware random-number generator, a bug pushed part of the process through a software-based generator with far less genuine randomness - in some cases tied to predictable values such as device serial numbers. That made it mathematically feasible for attackers to reconstruct private keys offline, without ever touching the physical device.

~1,367 BTC

Total drained (~$89m)

4,585

Addresses affected

30 Jul

First attack wave began

Coinkite confirmed other products in its lineup - TAPSIGNER, OPENDIME, and SATSCARD - were not affected, and released patched firmware for all affected models and release tracks.

What is a hardware wallet, and is self-custody still safer than an exchange?

A hardware wallet is a physical device that stores the private keys controlling access to cryptoassets offline, away from internet-connected computers, reducing exposure to remote hacking compared with keeping funds on an exchange. "Not your keys, not your crypto" became a popular phrase in crypto precisely because past exchange failures - including FTX in 2022 and Mt. Gox before it - showed that custodial platforms can fail or be hacked.

Hardware wallets vs exchange custody

Security researchers stress the Coldcard incident is not evidence that self-custody is inherently riskier than exchange custody, but rather that it carries a different category of risk: firmware and supply-chain integrity, rather than counterparty or exchange-solvency risk. According to blockchain security firm Blockaid, most crypto losses in the first half of 2026 came from compromised keys and operational security failures rather than smart contract exploits, and the Coldcard case fits that broader pattern.

Storage method Main risk highlighted Who controls the keys
Hardware wallet (self-custody) Firmware/supply-chain flaws, user error The individual holder
Centralised exchange Platform insolvency, hacking, withdrawal freezes The exchange
Software/mobile wallet Device malware, phishing The individual holder

Explore crypto with IG

Get started with a general IG account

How to protect crypto held on a hardware wallet

This is general information, not personalised advice, and not a comprehensive security checklist. Coinkite and independent researchers have pointed to a few broad principles relevant to any hardware wallet holder:

  • Keeping device firmware up to date, since patches like the one Coinkite issued address known vulnerabilities.
  • Using a strong BIP-39 passphrase (sometimes called a '25th word'), which independent researchers say would have made offline key reconstruction significantly harder even with the entropy flaw present.
  • Being cautious when moving funds off a suspected-compromised wallet, since security experts warned attackers could intercept transactions by offering higher fees - using out-of-band submission services was recommended in this case.
  • Treating any single storage method - hardware wallet, exchange, or software wallet - as carrying its own distinct risks, rather than assuming any one method is risk-free.

What this means for bitcoin price and market sentiment

Bitcoin was trading near $63,000 in the days following the exploit, within its recent range, even as the broader Crypto Fear and Greed Index sat in "Fear" territory. Data from social analytics firm Santiment showed Bitcoin's positive-to-negative social commentary ratio falling to roughly 0.58 bullish comments for every bearish one - among the most negative readings the firm has tracked, exceeding the sentiment shock around events like Mt. Gox and the COVID-19 "Black Thursday" crash. 

Some on-chain data also showed holders moving funds from self-custody back onto exchanges, according to CryptoQuant - the reverse of the pattern typically seen after an exchange failure such as FTX. For anyone following crypto markets, sentiment swings like this are a reminder that price action and security news can move independently of each other.

This sentiment shift does not necessarily reflect the scale of the dollar losses, which remain small next to historical events like the FTX collapse, but rather concern about a previously trusted category of "cold" storage. Past performance is not a reliable indicator of future results, and short-term sentiment swings do not determine longer-term price direction.

FAQ

Was Bitcoin itself hacked in the Coldcard incident?

No. Security commentators, including investor Anthony Pompliano, have distinguished the Coldcard firmware failure from the Bitcoin protocol itself. The flaw was specific to how certain Coldcard devices generated wallet seeds, not a weakness in Bitcoin's underlying blockchain.

How much was stolen in the Coldcard hack?

Galaxy Research tracked losses of roughly 1,367 BTC, worth approximately $89 million, drained from 4,585 addresses across multiple attack waves between 30 July and early August 2026.

Should I stop using a hardware wallet?

This article does not provide personalised advice. In general terms, hardware wallets remain a widely used method for storing cryptoassets offline; the Coldcard incident highlights the importance of keeping firmware updated and following manufacturer security guidance, rather than suggesting self-custody itself is inherently unsafe.

Start with a general IG account

Explore crypto markets with IG

Past performance is not a reliable indicator of future results.

Important to know

This information has been prepared by IG, a trading name of IG Markets Limited. In addition to the disclaimer below, the material on this page does not contain a record of our trading prices, or an offer of, or solicitation for, a transaction in any financial instrument. IG accepts no responsibility for any use that may be made of these comments and for any consequences that result. No representation or warranty is given as to the accuracy or completeness of this information. Consequently any person acting on it does so entirely at their own risk. Any research provided does not have regard to the specific investment objectives, financial situation and needs of any specific person who may receive it. It has not been prepared in accordance with legal requirements designed to promote the independence of investment research and as such is considered to be a marketing communication. Although we are not specifically constrained from dealing ahead of our recommendations we do not seek to take advantage of them before they are provided to our clients. See full non-independent research disclaimer and quarterly summary.

Sources: CoinDesk (31 Jul & 2 Aug 2026), Cryptopolitan (2 Aug 2026), TechTimes (1 Aug 2026), news.bitcoin.com (2 Aug 2026), cryptonews.net (2 Aug 2026), Bloomberg (3 Aug 2026), Galaxy Research, Santiment.