A firmware flaw in Coldcard hardware wallets, made by Canadian manufacturer Coinkite, has been exploited to drain roughly 1,367 BTC - worth close to $89 million - from thousands of addresses since 30 July 2026. The incident has unsettled the crypto market because it targeted "cold storage," long considered the safest way to hold bitcoin. Here's what actually happened, why security researchers say it isn't a flaw in bitcoin itself, and what UK crypto holders can take from it.
Coinkite Inc., maker of the Coldcard hardware wallet, notified users in late July 2026 that a security flaw in older firmware had compromised some wallets. Attackers exploited the flaw across several distinct waves: roughly 594 BTC (about $38 million) was drained in the first wave on 30 July, rising to about 1,082 BTC by 1 August, and reaching approximately 1,367 BTC (around $89 million) from 4,585 addresses by 2–3 August, according to on-chain analysis from Galaxy Research. A further wave was reported live on 3 August.
The issue traces back to a March 2021 firmware build affecting certain Coldcard Mk2 and Mk3 versions. Instead of routing seed-phrase generation through the device's dedicated hardware random-number generator, a bug pushed part of the process through a software-based generator with far less genuine randomness - in some cases tied to predictable values such as device serial numbers. That made it mathematically feasible for attackers to reconstruct private keys offline, without ever touching the physical device.
~1,367 BTC
Total drained (~$89m)
4,585
Addresses affected
30 Jul
First attack wave began
Coinkite confirmed other products in its lineup - TAPSIGNER, OPENDIME, and SATSCARD - were not affected, and released patched firmware for all affected models and release tracks.
A hardware wallet is a physical device that stores the private keys controlling access to cryptoassets offline, away from internet-connected computers, reducing exposure to remote hacking compared with keeping funds on an exchange. "Not your keys, not your crypto" became a popular phrase in crypto precisely because past exchange failures - including FTX in 2022 and Mt. Gox before it - showed that custodial platforms can fail or be hacked.
Security researchers stress the Coldcard incident is not evidence that self-custody is inherently riskier than exchange custody, but rather that it carries a different category of risk: firmware and supply-chain integrity, rather than counterparty or exchange-solvency risk. According to blockchain security firm Blockaid, most crypto losses in the first half of 2026 came from compromised keys and operational security failures rather than smart contract exploits, and the Coldcard case fits that broader pattern.
| Storage method | Main risk highlighted | Who controls the keys |
| Hardware wallet (self-custody) | Firmware/supply-chain flaws, user error | The individual holder |
| Centralised exchange | Platform insolvency, hacking, withdrawal freezes | The exchange |
| Software/mobile wallet | Device malware, phishing | The individual holder |
Explore crypto with IG
Get started with a general IG account
This is general information, not personalised advice, and not a comprehensive security checklist. Coinkite and independent researchers have pointed to a few broad principles relevant to any hardware wallet holder:
Bitcoin was trading near $63,000 in the days following the exploit, within its recent range, even as the broader Crypto Fear and Greed Index sat in "Fear" territory. Data from social analytics firm Santiment showed Bitcoin's positive-to-negative social commentary ratio falling to roughly 0.58 bullish comments for every bearish one - among the most negative readings the firm has tracked, exceeding the sentiment shock around events like Mt. Gox and the COVID-19 "Black Thursday" crash.
Some on-chain data also showed holders moving funds from self-custody back onto exchanges, according to CryptoQuant - the reverse of the pattern typically seen after an exchange failure such as FTX. For anyone following crypto markets, sentiment swings like this are a reminder that price action and security news can move independently of each other.
This sentiment shift does not necessarily reflect the scale of the dollar losses, which remain small next to historical events like the FTX collapse, but rather concern about a previously trusted category of "cold" storage. Past performance is not a reliable indicator of future results, and short-term sentiment swings do not determine longer-term price direction.
Was Bitcoin itself hacked in the Coldcard incident?
No. Security commentators, including investor Anthony Pompliano, have distinguished the Coldcard firmware failure from the Bitcoin protocol itself. The flaw was specific to how certain Coldcard devices generated wallet seeds, not a weakness in Bitcoin's underlying blockchain.
How much was stolen in the Coldcard hack?
Galaxy Research tracked losses of roughly 1,367 BTC, worth approximately $89 million, drained from 4,585 addresses across multiple attack waves between 30 July and early August 2026.
Should I stop using a hardware wallet?
This article does not provide personalised advice. In general terms, hardware wallets remain a widely used method for storing cryptoassets offline; the Coldcard incident highlights the importance of keeping firmware updated and following manufacturer security guidance, rather than suggesting self-custody itself is inherently unsafe.
Start with a general IG account
Explore crypto markets with IG
Past performance is not a reliable indicator of future results.
This information has been prepared by IG, a trading name of IG Markets Limited. In addition to the disclaimer below, the material on this page does not contain a record of our trading prices, or an offer of, or solicitation for, a transaction in any financial instrument. IG accepts no responsibility for any use that may be made of these comments and for any consequences that result. No representation or warranty is given as to the accuracy or completeness of this information. Consequently any person acting on it does so entirely at their own risk. Any research provided does not have regard to the specific investment objectives, financial situation and needs of any specific person who may receive it. It has not been prepared in accordance with legal requirements designed to promote the independence of investment research and as such is considered to be a marketing communication. Although we are not specifically constrained from dealing ahead of our recommendations we do not seek to take advantage of them before they are provided to our clients. See full non-independent research disclaimer and quarterly summary.
Sources: CoinDesk (31 Jul & 2 Aug 2026), Cryptopolitan (2 Aug 2026), TechTimes (1 Aug 2026), news.bitcoin.com (2 Aug 2026), cryptonews.net (2 Aug 2026), Bloomberg (3 Aug 2026), Galaxy Research, Santiment.