Coldcard hack drains 1,367 BTC: predictable seed phrases expose $86M
The Coldcard vulnerability demonstrates how flawed random-number generation can compromise hardware wallets, a critical lesson for cryptographic security. Over 4,500 wallets lost $86M in Bitcoin as attackers reverse-engineered deterministic seed phrases. This ongoing breach forces a reevaluation of cold storage trust assumptions.
Key Takeaways
- The Coldcard vulnerability demonstrates how flawed random-number generation can compromise hardware wallets, a critical lesson for cryptographic security.
- Over 4,500 wallets lost $86M in Bitcoin as attackers reverse-engineered deterministic seed phrases.
- This ongoing breach forces a reevaluation of cold storage trust assumptions.
Mentioned
Key Intelligence
Key Facts
- 1Attackers exploited a predictable seed-phrase vulnerability in Coinkite Coldcard cold wallets, caused by a fallback RNG mechanism that used deterministic values like serial numbers.
- 2As of August 3, 2026, 1,367 BTC (approximately $86 million) had been drained from more than 4,500 wallets, according to Galaxy Research.
- 3Coinkite notified users of the compromised keys late last week; the attack was first reported by victims on July 29, with funds drained in minutes.
- 4Block Inc.’s engineering team discovered that the flawed seed generation allowed attackers to reverse-engineer wallet keys without physical access.
- 5Victim Jonathan Goodman reported losing funds from three wallets between 9:36 and 9:43 p.m. on July 29, highlighting the automated speed of the heist.
- 6Experts warn the incident shatters the perception of cold wallets being inherently secure, as offline isolation cannot protect against broken cryptographic math.
It exposes the fallacy of your crypto being offline. The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.
Commenting on the Coldcard vulnerability
Drained from over 4,500 Coldcard wallets as of Aug 3, 2026
Analysis
This incident shatters the perceived inviolability of cold storage and highlights the dire consequences of poor entropy in cryptographic systems. For cybersecurity professionals, it’s a real-world case study in RNG failure that demands urgent review of hardware wallet security architectures. Every security feature beyond strong key generation is moot if the foundational randomness is broken.
Hackers have exploited a critical software vulnerability in Coinkite’s Coldcard hardware wallets, long regarded as one of the most secure methods for storing Bitcoin offline. The flaw, rooted in a predictable seed-phrase generation process, has already led to the theft of approximately 1,367 BTC—worth roughly $86 million—from over 4,500 wallets as of August 3, 2026, according to data from Galaxy Research. The attack is ongoing, and the fallout is sending shockwaves through the cryptocurrency and cybersecurity communities, challenging the fundamental assumption that cold storage is impervious to remote theft.
The price of Bitcoin itself, around $62,900 per token at the time of reporting, could face downward pressure if large-scale liquidations occur from stolen funds being sold on exchanges.
The vulnerability stems from Coinkite’s implementation of the random-number generator (RNG) used to create the 12- or 24-word seed phrases that control access to Bitcoin funds. Instead of relying solely on cryptographically secure entropy, Coldcard firmware contained a fallback mechanism that, under certain conditions, generated keys using deterministic values such as the device’s serial number. Block Inc.’s engineering team identified the flaw, revealing that attackers could reverse-engineer these deterministic inputs to compute the corresponding seed phrases without ever needing physical access to the device. This effectively converts a hardware wallet into a predictable password generator, undermining its entire security model.
The attack first came to light late last week when Coinkite issued a notice to users about the compromised keys. By then, funds were already moving. Victim Jonathan Goodman described his disbelief after checking his wallet on July 29: “Between 9:36 and 9:43 pm, all three of my wallets were completely drained.” The speed and precision of the thefts indicate that attackers automated the process, likely by scanning the blockchain for wallets associated with known Coldcard firmware versions and then mass-computing the weak seeds.
The incident raises profound concerns about the supply chain and software integrity of hardware wallets. Coldcard devices are popular among security-conscious Bitcoin holders precisely because they are designed to operate air-gapped, never connecting to the internet. Yet, as Aneirin Flynn, CEO of cybersecurity firm Failsafe, noted, “It exposes the fallacy of your crypto being offline. The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.” This statement underscores a bitter truth: cold storage is only as strong as the cryptographic randomness at its core. When entropy fails, no amount of physical isolation can protect funds.
The financial impact is significant but perhaps more damaging is the erosion of trust. The $86 million stolen so far may represent only the earliest victims; if the flawed seed generation dates back to older firmware versions, the total vulnerable address space could be far larger. Galaxy’s initial count of 4,500 affected wallets is likely to grow as more users check their balances. The price of Bitcoin itself, around $62,900 per token at the time of reporting, could face downward pressure if large-scale liquidations occur from stolen funds being sold on exchanges. However, blockchain analysis firms are likely monitoring the hacker-controlled addresses, which may limit the ability to cash out.
From a regulatory perspective, this breach could accelerate calls for mandatory security standards and third-party audits for cryptocurrency wallet vendors. The market for hardware wallets has long relied on community trust and open-source scrutiny, but the Coldcard flaw—apparently present in proprietary firmware—escaped detection until now. Coinkite is expected to release a firmware update to fix the RNG fallback, and users are being urged to move funds to new wallets generated with a patched device. Many will question whether the brand can survive such a catastrophic trust breach.
What to Watch
The attack also highlights the broader challenge of deterministic attacks in blockchain security. Non-random key generation has been the root cause of several past cryptocurrency heists, including early Bitcoin brain-wallet thefts and Ethereum address collisions. This incident provides a fresh reminder that even dedicated security hardware can harbor fatal flaws if rigorous entropy standards are not enforced. As the industry moves toward multi-party computation (MPC) and hardware security modules (HSMs) for institutional custody, the Coldcard failure will likely be cited as a case study in the risks of single-point entropy failure.
Looking ahead, the episode is poised to reshape the hardware wallet landscape. Competitors like Ledger and Trezor may see a short-term influx of users, but they too face pressure to prove their own RNG implementations are robust. Regulators, particularly in jurisdictions like the EU with its Markets in Crypto-Assets (MiCA) framework, may require wallet providers to submit to regular, independent cryptographic audits. For individual Bitcoin holders, the lesson is stark: even a cold wallet is a complex system where any component—from the RNG to the display—can be a point of failure. The attack is ongoing, and the full scope will only become clear once Coinkite completes its post-mortem and more victims come forward. Until then, the cryptocurrency world is left to grapple with the uncomfortable reality that its safest hiding place may not be safe at all.
Sources
Sources
Based on 2 source articles- The Business TimesHackers hit Bitcoin’s safest hiding place in ongoing attackAug 3, 2026
- Suvashree GhoshHackers target bitcoin's safest hiding place in ongoing attackAug 3, 2026
Cite This Page
"Coldcard hack drains 1,367 BTC: predictable seed phrases expose $86M." Cyber Intelligence Brief, August 4, 2026. https://getcyberbrief.com/story/coldcard-hack-drains-1367-btc-predictable-seed-phrases
How we covered this story
Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.
Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.
Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.
See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.
| Signal on this page | What it tells you |
|---|---|
| Verified by N sources | Independent corroboration count. N≥2 is our confidence floor; N=1 is marked explicitly. |
| Impact score (1-10) | Regulatory + financial + operational weight. 8+ signals an experienced-operator action item. |
| Sentiment | Five-tier classification trained on labeled cybersecurity-specific corpora. |
| Timeline | Where applicable, the related-events sequence that contextualizes today's development. |