< Back to situation

[REVISION HISTORY]

Coldcard flaw fuels $88M Bitcoin theft

Updated 6 times since CLSTR started tracking revisions of this situation.

What changed

2026-08-02 21:54 UTC → 2026-08-03 01:22 UTC · added removed

Coldcard flaw fuels $70‑$90M $88M Bitcoin theft

A firmware flaw introduced in a The March 2021 firmware update for Coldcard hardware wallets (Mk2, Mk3, Mk4, Mk5 (Mk2‑Mk5 and Q) reduced seed‑phrase entropy, making private keys guessable. Researchers at mathematically predictable. Galaxy Research identified traced three coordinated attack waves that have siphoned a total of 1,367.05 BTC – roughly $88‑$90 million – 1,367 BTC (about $88‑$89 million) from 4,585 addresses. The first two waves funneled funds to a small set of drained about 1,160 BTC from 2,674 wallets using shared P2WPKH collector addresses; the addresses. A third wave used separate wave, observed in late July‑early August 2026, withdrew 207.73 BTC from 1,912 wallets, routing funds to individual P2WSH vaults, vaults and averaging 6.37 victim wallets per transaction and draining 207.73 BTC from 1,912 wallets. transaction. Most of the stolen coins remain unspent, concentrated in a few attacker wallets, suggesting a hold‑before‑liquidation strategy. Victims are predominantly The breach triggered a surge in on‑chain activity, with sub‑1 BTC transfers spiking to roughly 39,600 BTC in a single day—the highest level since the FTX collapse. Victims, largely long‑term holders (average dormancy ≈ 3.2 years). In response to the theft, many years), are moving Bitcoin to centralized exchanges, driving a spike in sub‑1 BTC transactions and creating the strongest retail inflow to exchanges since February. Researchers warn that any single‑signature Coldcard address generated after the March 2021 firmware update remains vulnerable and advise users to migrate funds vulnerable. Users are urged to stop creating new wallets with on the flawed firmware, update to the patched version, generate fresh seeds. seeds, and relocate funds to secure addresses or reputable exchanges. The episode has intensified continues to fuel debate over self‑custody versus exchange storage, prompting storage and prompts calls for immediate hardware upgrades or replacement of affected Coldcard devices. replacement.

Versions

  1. 2026-08-03 01:22 UTC Coldcard flaw fuels $88M Bitcoin theft
  2. 2026-08-02 21:54 UTC Coldcard flaw fuels $70‑$90M Bitcoin theft
  3. 2026-08-02 17:50 UTC Coldcard flaw fuels $70‑$90M Bitcoin theft
  4. 2026-08-02 10:23 UTC Coldcard flaw fuels $70‑$90M Bitcoin theft
  5. 2026-08-02 07:03 UTC Coldcard flaw fuels $70‑$90M Bitcoin theft
  6. 2026-08-02 02:28 UTC Coldcard flaw fuels $70‑$90M Bitcoin theft
  7. 2026-08-01 22:35 UTC Coldcard wallet flaw and Bitcoin impact

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.