Coldcard was supposed to be the paranoid option the hardware wallet people chose solely because they didn’t trust anything else with their Bitcoin. Then, on July 30, someone started draining those wallets anyway.
By the time researchers at Galaxy Digital had finished assessing the incident, roughly 1,816 BTC, worth close to $116 million, had been moved from more than 5,200 addresses across four separate waves. The largest of those sweeps alone took 1,082 BTC from 1,196 wallets in just 41 minutes.
This wasn’t a case of someone falling for a phishing email or having their device stolen. The vulnerability went much further back. A firmware build released in March 2021 quietly bypassed the chip designed to generate true randomness and instead relied on a predictable source.
That distinction turned out to matter enormously. Because the randomness used to generate the wallet seeds was predictable, an attacker could reproduce a victim’s seed phrase from a laptop without ever having physical access to the Coldcard itself.
But what makes the incident particularly troubling was the profile of the victims.
Galaxy’s review of victim reports found that the median stolen Bitcoin had been sitting untouched for around three and a half years. Some 88% of the affected wallets had been dormant for at least a year.
These weren’t active traders taking unnecessary risks or users chasing the latest yield opportunity. In many cases, they were doing exactly what Bitcoin security advice has recommended for years: buy a hardware wallet, write down the seed phrase, store it somewhere safe and leave the coins alone.
And yet, that caution wasn’t enough. For people who bought Coldcard specifically because they wanted the more security-conscious option, that’s probably the most unsettling part of the entire incident.
Jameson Lopp, Casa's co-founder, made a point about this that's more useful than the usual "not your keys, not your coins" line. In his argument he said, real verification of complex hardware is basically impossible for almost anyone, so self-custody was never actually trustless. You're just trusting a smaller set of vendors and auditors instead of an exchange.
There's a second wave behind this one, and it isn't technical. Recovery specialists working these cases say the days right after a hack like this are when scammers move fastest reaching out to panicked victims claiming they can trace or recover the funds for an upfront fee. It's the seed-phrase problem in reverse, whoever's able to help you get back in can also get in without you.
Coinkite has pushed a firmware fix and is telling anyone who generated a seed on the affected builds to migrate immediately, no exceptions. If there's a lesson in the story of the guy who was shown a billion-dollar wallet that turned out to hold ten bucks, this is its mirror image, a wallet you never open is still only as safe as code you never read.