For years, hardware wallets were sold as the safest place to store Bitcoin, devices that never touch the internet, and therefore can’t be hacked remotely. That assumption is now facing its biggest test.
A ₹820-crore Bitcoin heist has exposed a bug that sat undetected inside Coldcard, one of crypto’s most trusted cold-storage devices, for nearly five years before anyone found it.
Blockchain investigators tracked roughly 1,367 Bitcoin, worth close to $86 million, drained from more than 4,585 wallets linked to Coldcard hardware devices in a series of coordinated attacks that began on July 30, 2026. Coinkite, the Canadian company that makes Coldcard, has confirmed the vulnerability, apologised publicly, halted shipments of affected units, and released emergency firmware fixes.
Investigators say the theft may not be over.
Check Live: Crypto Option Chain India — Live Bitcoin & Ethereum
What Happened in the Coldcard Wallet Hack
A hardware wallet like Coldcard does not store Bitcoin itself. Bitcoin lives on the blockchain; the device stores the private keys, generated from a 12 to 24-word “seed phrase,” that prove ownership and unlock access to funds. As long as that seed phrase is generated with true randomness and never leaves the device, the funds are considered safe, even if the device stays offline forever.
That is exactly what broke. A coding error introduced in Coldcard firmware version 4.0.0 in March 2021 meant that, under certain conditions, the device silently fell back on a predictable software-based random number generator instead of its dedicated hardware randomness chip. The seed phrases these devices produced looked normal but were far easier to reconstruct than users were told.
Security researchers, including blockchain analytics firm Galaxy Research and Block’s Bitcoin engineering team, say attackers likely used AI-assisted brute-force techniques to rebuild thousands of these weakened seed phrases entirely offline, with no need to ever touch a victim’s physical device.
Timeline: How the Coldcard Bitcoin Theft Unfolded
| Date | Development | Cumulative BTC Drained | Approx. Value | Wallets Affected |
|---|---|---|---|---|
| July 29, 2026 | Individual victims’ wallets emptied (e.g., Jonathan Goodman) | — | — | Isolated cases |
| July 30, 2026 | First coordinated sweep, a 41-minute window on Mk3 devices | ~594 BTC, revised to 1,082.65 BTC | $38M–$70.2M | 500, revised to 1,196 addresses |
| July 31, 2026 | Coinkite issues first advisory, releases fixed Mk3 firmware (4.2.0) | 1,082.65 BTC | ~$70.2M | 1,196 addresses |
| August 1, 2026 | Second wave found; advisory expands to Mk4, Mk5, Coldcard Q | 1,158.66 BTC | ~$75.1M | 2,673 addresses |
| August 2, 2026 | Third wave adds 207.73 BTC | ~1,367 BTC | ~$86M–$89M | 4,585 addresses |
| August 3, 2026 | Researchers flag signs of a possible fourth wave; probe ongoing | Still rising | Still rising | Still rising |
None of the stolen Bitcoin has moved out of the attacker-controlled addresses so far, which Galaxy Research calls unusual for a theft this size.
Has Coinkite Confirmed the Coldcard Hack?
Yes. Unlike many crypto exploits that companies downplay for days, Coinkite confirmed the flaw within roughly 30 hours of the first attack wave. CEO Rodolfo Novak, widely known as NVK, posted a public apology on X taking responsibility for the firmware bug. “I’m sorry and I’m devastated,” he wrote, urging every Coldcard owner to move funds immediately using the company’s updated guidance.
Coinkite’s official advisory confirms Mk3 devices running firmware 4.0.1 through 4.1.9 are affected, and that Mk4, Mk5 and Coldcard Q devices running pre-fix firmware carry roughly 72 bits of entropy instead of the expected 128, weaker, though not as severely compromised as the Mk3. The company’s other products, TAPSIGNER, OPENDIME and SATSCARD, are not affected.
| Device | Affected Firmware | Fixed Firmware |
|---|---|---|
| Coldcard Mk3 | 4.0.1 to 4.1.9 | 4.2.0 or later |
| Coldcard Mk4 / Mk5 | Pre-fix builds (~72-bit entropy) | 5.6.0 or later |
| Coldcard Q | Pre-fix builds | 1.5.0Q or later |
| TAPSIGNER / OPENDIME / SATSCARD | Not affected | Not applicable |
Crucially, Coinkite has stressed that installing the new firmware does not protect funds already sitting in a seed generated on vulnerable firmware. Affected users must generate an entirely new wallet on patched firmware and move funds across, updating alone changes nothing for old seeds.
Jonathan Goodman’s Case: How ₹11 Crore Vanished in Seven Minutes
Among the most widely shared accounts of the Coldcard wallet hack is that of Toronto-based entrepreneur Jonathan Goodman. In a post on X, Goodman said 18.25245043 BTC, which he valued at roughly $1.6 million Canadian dollars, or nearly ₹11 crore at current exchange rates, was swept from every wallet he controlled between 9:36 pm and 9:43 pm on July 29.
Goodman said his Coldcard device had been kept in a bank safety deposit box and had never touched the internet, and that he’d followed standard self-custody best practices, including storing backup information separately.
He has said he is filing reports with Toronto Police and the Ontario Securities Commission, though he does not expect to recover the funds. His original thread, posted from handle @itscoachgoodman, can be viewed at x.com/itscoachgoodman/status/2083527082223563157.
Coinkite’s advisory itself warns that opportunistic “recovery services” have begun contacting hack victims. The company has been explicit that it will never need a user’s seed phrase to help with firmware updates, and that anyone requesting a seed phrase or offering guaranteed fund recovery should be treated as a scammer.
More Coldcard Users Report Losses
Goodman isn’t an isolated case. Multiple Reddit users have described similar losses from Coldcard wallets built up over years of disciplined dollar-cost-averaging investing, including one user who said more than 3 BTC disappeared after years of weekly purchases, and another who said roughly 1 BTC, accumulated over years and protected with a steel backup plate, fireproof bag and a safe, was drained the same way. Both had specifically chosen Coldcard for its reputation as one of the more security-focused hardware wallets on the market.
Market Reaction: Self-Custody Under the Scanner
The Coldcard hack has reopened a long-running debate in crypto: is self-custody actually safer than trusting an exchange? Binance co-founder Changpeng “CZ” Zhao weighed in on X, noting that firmware fixes cannot retroactively secure wallets that were already generated with the flawed randomness. Blockaid, a blockchain security firm, has pointed out that most crypto losses in the first half of 2026 stemmed from compromised keys and operational failures like this one rather than smart-contract exploits.
Reports suggest some retail holders have started moving Bitcoin back onto centralised exchanges in the short term, an unusual reversal of crypto’s long-standing “not your keys, not your coins” philosophy.
Bitcoin itself has stayed relatively range-bound through the episode, trading near $63,000 on August 3, 2026. Part of that stability held even as a separate, unrelated development added supply pressure: Trump Media & Technology Group, the company behind Truth Social, sold another 2,628 BTC (about $165 million) on August 2, taking its 2026 Bitcoin sales past 7,281 BTC (~$545 million).
Market commentary has treated the two developments as distinct, Coldcard-linked outflows and Trump Media’s ongoing treasury sales, rather than one driving the other, suggesting the exploit has so far been read as a wallet-specific failure rather than a systemic risk to Bitcoin itself.
What Should Coldcard Owners Do Right Now
- Check which firmware version generated your current seed phrase before assuming you are safe
- If you used fewer than 50 private dice rolls for extra entropy, or no BIP-39 passphrase, treat your existing seed as compromised
- Update to the latest fixed firmware, then generate a brand-new seed, do not simply reuse the old one
- Move funds to the new wallet using a high enough transaction fee to get priority confirmation
- Ignore anyone offering “recovery” help who asks for your seed phrase; Coinkite has confirmed this is never required
- Follow Coinkite’s official advisory and the @COLDCARDwallet account directly, rather than relying on secondhand social posts
What This Means for Indian Crypto Investors
There’s no confirmed report yet of an Indian holder among the wallets hit by the Coldcard wallet hack, and Coldcard remains a niche, imported device rather than an exchange product widely distributed in India. Even so, the Coldcard hack is relevant for India’s crypto investor base for three reasons.
First, it lands just months after India’s own high-profile custody failures, the roughly ₹1,950-crore WazirX hack in 2024 and the CoinDCX breach in 2025, reinforcing that both centralised exchanges and self-custody hardware carry distinct risks, not that one is automatically safer than the other.
Second, Indian investors who moved Bitcoin into cold storage specifically to avoid exchange-side risk are the exact profile this flaw affects, and should check their device and firmware history. Third, a confirmed theft of this size tends to weigh on near-term crypto sentiment and trading volumes on Indian platforms, even without direct exposure.
Also Check: Crypto Price Today — Bitcoin, Ethereum & Live Rates
NiftyTrader Desk View
The Coldcard wallet hack isn’t really a Bitcoin hack, it’s a randomness hack, and that distinction matters. The underlying flaw didn’t break Bitcoin’s cryptography; it undermined the quality of the random numbers feeding into it, which is arguably more dangerous because it can lie dormant and pass ordinary testing for years, exactly as this one did since 2021.
For investors, the takeaway isn’t that self-custody has failed, it’s that self-custody is only as strong as the firmware and entropy sources behind it. Verification habits like dice-roll entropy and passphrases, once seen as optional extra steps, are now the difference between a safe wallet and a five-minute drain.
Expect continued scrutiny of other hardware wallet makers’ random number generation as researchers stress-test the broader industry in the coming weeks. “Not your keys, not your coins” still holds as a principle, this episode simply adds a corollary: those keys are only as trustworthy as the code that generated them.
Read Next: India’s Stock Market Gets a New Closing System Today: New F&O Closing Auction Rules Explained
Frequently Asked Questions
What is the Coldcard wallet hack?
It’s a security flaw in Coldcard hardware wallets, made by Coinkite, that caused some devices to generate Bitcoin seed phrases using weak, predictable randomness instead of true hardware-based randomness, letting attackers reconstruct seed phrases and steal funds without physical access to the device.
How much Bitcoin was stolen in the Coldcard hack?
Galaxy Research estimates roughly 1,367 BTC, worth about $86–89 million (nearly ₹820 crore), has been drained from more than 4,585 wallets so far, across multiple attack waves since July 30, 2026, with the total still being tracked.
Has Coinkite confirmed the Coldcard vulnerability?
Yes. Coinkite issued an official security advisory, its CEO publicly apologised and took responsibility, the company halted shipments of affected devices, and it has released fixed firmware for all affected models.
Is Bitcoin itself hacked?
No. Bitcoin’s underlying blockchain and cryptography were not compromised. The flaw was specific to how certain Coldcard devices generated seed phrases, not to Bitcoin as a network or asset.
What should Coldcard owners do to protect their funds?
Update to the latest fixed firmware, generate a completely new seed phrase rather than reusing the old one, and move funds to the new wallet, unless the original seed was created using at least 50 private dice rolls or a strong BIP-39 passphrase.
Are other hardware wallets like Ledger or Trezor affected?
No confirmed reports link this specific vulnerability to Ledger, Trezor or other hardware wallet brands. The flaw traced back to a coding error unique to Coldcard’s firmware.
Can the stolen Bitcoin be recovered or traced?
The stolen funds remain visible on the blockchain and haven’t moved out of the attacker’s addresses so far, which researchers are actively tracking. But Bitcoin transactions are irreversible, so recovery would depend on the attacker being identified and funds being frozen if they ever reach a regulated exchange, there’s no guaranteed path to getting the coins back.
Can AI really crack a Bitcoin seed phrase?
Not under normal conditions, a properly generated 12-word seed phrase has too many possible combinations to brute-force. This case was different because the underlying randomness was already weak, which narrowed the search space enough that researchers believe AI-assisted computing made offline brute-forcing feasible.
Disclaimer:
This article is based on publicly available reports, official statements, and user claims available at the time of publication. As the investigation is ongoing, some details may change as new information emerges. Readers should refer to official advisories before making any security or investment decisions.
