Friday, September 18, 2026
BTC: $78,168 +2.45% ETH: $2,514 +3.39% SOL: $106.50 +6.85% XRP: $1.34 +3.17% ADA: $0.2161 +9.23%

Coldcard Bitcoin Hack Losses Confirmed at $115 Million as Bug Traced to Old Code Flaw

Galaxy Research confirms $115 million in bitcoin stolen through a Coldcard firmware bug that went unnoticed since 2021, with at least 15 attackers exploiting the flaw.

At least $115 million in bitcoin has been drained from Coldcard hardware wallet users after a seed-generation bug sat unnoticed for more than four years, Galaxy Research confirmed.

The firm said it has spoken with more than 200 victims. It traced roughly 1,596 bitcoin stolen from about 7,300 addresses, valued at $115 million using the price of bitcoin at the time coins were taken. Galaxy said losses could still exceed $130 million as it continues confirming the full scope.

Coinkite, the Toronto company behind Coldcard, said in a statement that the bug “silently went unnoticed” and that “its potential impact grew with every release” of its products. The flaw dates to a major 2021 software overhaul, according to a CoinDesk investigation: firmware version 4.0.0, released March 17, 2021, billed as “All New Code, Same Great Features.”

The vulnerability was not in the wallet itself. It was in how the wallet generated seed phrases. Coldcard devices were supposed to draw randomness from a dedicated hardware generator. A configuration error instead routed seed creation to a simpler software generator using device and timing data. Block’s Bitcoin engineering and security team traced the failure to a library called libngu: it checked only whether a setting existed, not whether it was turned on or off. Firmware built normally while using the wrong generator.

That made the error invisible to anyone who did not follow the seed-generation process end to end. The source code was public. The correct hardware component was present in the finished firmware. Reviewers confirmed the component existed without verifying which generator the device actually used. Coinkite said AI-assisted code reviews it ran before the theft also missed the error. Tests with several leading AI models after the incident failed to identify it as well.

The numbers tell the rest. Coinkite estimates newer devices produced seeds with 72 bits of randomness instead of the intended 128. That is roughly 72 quadrillion times fewer possible seeds. Block said affected Mk2 and Mk3 devices received no secure randomness through the process at all. Mk4, Q, and Mk5 devices received some, but the software kept only a small share.

At least 15 different attackers exploited the flaw independently, Alex Thorn, Galaxy’s head of research, estimated on August 4. None needed physical access to a device. The typical stolen coin had sat untouched for 3.5 years. Per prior Galaxy Research, 88% of pilfered funds were at least a year old. Hackers began taking bitcoin stored on Coldcard wallets on July 31, according to Bitcoin Magazine.

Jonathan Goodman, a Toronto entrepreneur, reported 18.25 bitcoin stolen on July 29. That was worth just over $1.17 million at the time. He kept his Coldcard in a safe deposit box. The seed phrase was stored in a second safe deposit box. The device was never connected to the internet. “Perhaps the hardest part about this is that I did everything right,” Goodman wrote in an August 1 post on X.

Bitcoin developer James O’Beirne said he questioned the seed-generation process while auditing Coldcard’s code in May 2025 and raised the possibility of a defect with Coinkite. The company replied that a genuine problem would probably have been discovered already, per O’Beirne. He also linked the GitHub account “switck” to Coinkite co-founder Peter Gray, identifying 58 code changes published under that account carrying the same cryptographic signature Gray used on his own changes. O’Beirne wrote that Gray was “the same guy that shrugged off my report of the possibility of the defect in May 2025.” Coinkite has not responded to the identity claim and did not respond to CoinDesk’s request for comment.

Coinkite has released fixed firmware for all affected Coldcard models. The update corrects future seed generation but does not strengthen seeds already created with vulnerable software. Affected users must install the patch, generate a new seed, and move their bitcoin to addresses derived from it, per the company’s advisory.

Bobby Gray, founder of TEXITcoin, told CoinDesk: “Air-gapped systems help, but they are not a perfect fix. Security has to begin with how the keys are generated and continue through every part of the custody process.”

What remains unknown is the final loss total. Galaxy is still confirming how much was stolen. The identities of the attackers have not been established. Coinkite has promised to publish a fuller account of the failure but has not yet done so.