The Coldcard Hack
The safest place to keep Bitcoin was supposed to be a device that never touches the internet. Over five days, attackers drained more than $100M from those devices without physically touching a single one. Here's what went wrong, and why it started five years before anyone lost a coin.

Hardware wallets are supposed to end the argument. The owner keeps keys on a device that never connects to anything, signs transactions offline, and leaves nothing for a remote attacker to reach. For years that was the whole pitch for Coldcard, the Bitcoin-only signer made by Canadian firm Coinkite. It is why serious holders trusted it with life-changing sums.
On July 30, 2026, an attacker swept 1,196 addresses and took roughly 1,082 BTC in a single 41-minute window. The sweeping continued for days afterward, with Galaxy Research confirming 1,596 BTC taken across 7,300 addresses. Galaxy put the ceiling at 2,055, worth north of $100M by the time Bloomberg picked it up. The firm called the exploit ongoing and urged anyone still holding single-signature funds on a Coldcard to move them immediately.
The victims did nothing wrong, and that is the part that unsettled people. One Canadian, coach Jonathan Goodman, posted that 18.25 BTC left his wallets in a seven-minute span. His keys sat in a safety deposit box that had never been online.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack. My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
He was correct, and the failure was not in his opsec but in math that had been wrong since 2021.
What actually failed
Every wallet is only as strong as the randomness used to create its seed. Generate that seed with a proper source of entropy and the number of possible keys is so large that guessing one is effectively impossible. Get the randomness wrong and the whole guarantee collapses, because now an attacker can reproduce the same keys the device did.
A firmware integration error introduced in March 2021 routed seed generation to a deterministic software pseudo-random number generator. It quietly bypassed the STM32 hardware RNG on the device. Affected units produced seeds that looked random but were predictable. The offline device did exactly its job, signing only what its owner approved, and it made no difference. The key was already guessable the day it was created.
What this was not
Bitcoin itself was never touched. As investor Anthony Pompliano pointed out, the failure lived in how one vendor’s firmware generated seeds, not in the protocol, the consensus rules, or the ledger. The network ran normally the entire time. This was a signer compromise, delivered at scale.
Coldcard losses, as tracked on-chain
Figures per Galaxy Research on-chain analysis and reporting by Decrypt, Fortune, and Bloomberg, as of August 4, 2026. Outlets disagree on the basis: Fortune counted 1,816 BTC across 5,200+ addresses the same day Galaxy confirmed 1,596 across 7,300. Totals were still climbing at publication. Galaxy noted Waves 1 and 2 may share an operator, and cautioned that later waves should not be assumed to involve the same attacker.
The response made it worse
The technical failure was bad enough on its own, and the handling of it turned the incident into a second story. To warn people, Coinkite emailed every customer address it could reach from its store and newsletter records, some dating back to 2019. That contradicted the company’s earlier position that it deleted customer data 90 days after purchase and offered anonymous checkout. Coinkite later admitted it had retained those purchase emails the whole time. In one move, a privacy-first brand tied real identities to Bitcoin holdings. It also confirmed it had been sitting on a customer list it said did not exist.
The tracing help that usually follows a theft this size was slower to arrive. On-chain investigator ZachXBT declined to work the case, saying his time goes to communities that support his investigations. Galaxy did flag roughly 600 suspected attacker addresses to federal investigators and compliance firms, but the funds moved fast. Cold-storage users who assumed offline meant untraceable found the opposite was true for the people chasing them.
The defect shipped in 2021 and waited
The lesson for anyone holding keys
The uncomfortable takeaway is that “offline” was never the whole security model. Air-gapping protects a key from being reached, and does nothing about a key that was weak the moment it was born. Trust in a signer is really trust in the vendor’s firmware, their build process, and their entropy. Almost no one verifies those assumptions before wiring in eight figures.
That gap is where we work, and a key and signer compromise does not have to start with a phishing email or a malicious signature request. It can start with a supply-chain defect in the device its owner trusted most. An OpSec review exists to surface exactly these assumptions before an attacker does. Continuous monitoring exists to catch the drain in minutes rather than after the fifth wave. If your team custodies keys, or builds the tools that other teams custody keys with, we’d like to hear from you.
About Common Defense
Common Defense is an AI cyber lab built by security veterans and AI researchers, whose team has helped protect more than $300B in assets across 1,100+ security engagements. We help AI companies, fintechs, and crypto protocols secure the communication channels and operations that attackers target most.
