Logo
My Crypto News AI

A Five-Year-Old Firmware Bug Just Cost Bitcoin Users $116 Million: Here's What Went Wrong

A firmware bug released in March 2021 caused Coldcard hardware wallets to generate weak encryption keys, allowing attackers to steal approximately $116 million in Bitcoin starting July 30, 2026. The vulnerability affected seed generation, the process that creates the master key protecting a wallet. Instead of using the device's secure hardware-based randomness, affected Coldcard units fell back on a weaker software random number generator, cutting effective key strength from 128 bits down to as little as 40 bits, low enough to brute-force without ever touching the physical device.

This marks the third-largest crypto hack of 2026, bringing the year's total losses past $1.2 billion across 276 incidents. The attack unfolded in at least four waves between July 30 and August 4, 2026, with Galaxy Research tracking approximately 1,816 Bitcoin stolen from more than 5,200 addresses. The stolen funds have pooled at a small number of attacker-controlled addresses with minimal laundering activity so far, suggesting the perpetrators may still be working out how to move such a large sum without drawing regulatory attention.

How Did Attackers Exploit a Hardware Wallet?

The vulnerability stems from a build configuration error in Coldcard firmware version 4.0.1. When generating a wallet seed, the software was supposed to pull randomness from the device's dedicated hardware entropy source. Instead, a misconfiguration caused it to fall back on a weak software-based random number generator. This might sound like a small technical detail, but it has enormous security implications. Randomness is the foundation of cryptography; weak randomness means weak keys, and weak keys can be cracked.

What makes this exploit particularly alarming is that attackers did not need physical access to the Coldcard device. Because the vulnerability weakens the seed itself, not the device's physical security, attackers could brute-force the resulting private key using standard computing power. This breaks a core assumption many users make about hardware wallets: that they are secure because they are offline and isolated from the internet. In this case, the weakness was baked into the seed at creation time, making the device's physical isolation irrelevant.

Why Didn't a Firmware Update Fix This?

Coinkite, the company behind Coldcard, released a patch to fix the firmware bug. However, updating the firmware only prevents new wallets from being generated with weak randomness. It does not retroactively fix seeds that were already created on vulnerable firmware. This is a critical distinction that many users misunderstood. If a user generated a Coldcard seed between March 2021 and the patch date, that seed is permanently compromised and should be treated as such, regardless of whether the device's firmware has since been updated.

The attack timeline reveals how quickly the vulnerability was exploited once discovered. On July 30, 2026, attackers began sweeping Bitcoin out of affected wallets. Within just 25 minutes, roughly 594 Bitcoin, worth close to $38 million at the time, had been moved from approximately 500 wallets into a single consolidation address. Three additional waves followed over the next four days, each moving hundreds of millions of dollars in stolen funds.

Steps to Protect Yourself If You Own a Coldcard

  • Check Your Seed Generation Date: If you created a Coldcard wallet seed between March 2021 and the recent patch, treat that seed as compromised regardless of your current firmware version.
  • Generate a New Seed on Updated Hardware: Create a brand-new seed using a Coldcard with the latest patched firmware, or consider using a different hardware wallet manufacturer entirely.
  • Migrate Your Funds Carefully: Transfer your Bitcoin to the new wallet, starting with a small test transaction before moving the remainder to confirm the new wallet is working correctly.
  • Verify the New Wallet Fingerprint: Double-check that the new wallet's fingerprint and receive address match what you expect before sending large amounts of funds.

What Does This Say About Cold Storage Security?

The Coldcard hack reinforces a sobering reality: self-custody moves risk rather than eliminating it. A wallet is only as trustworthy as the process that generated its key. Firmware quality and entropy generation are just as critical to scrutinize as the device's physical security features. Open-source code and third-party audits improve security but are not guarantees, especially when subtle configuration errors can slip through.

Transaction analysis shows that most stolen funds have pooled at a small number of attacker-controlled addresses with limited onward movement. Only 64.9 Bitcoin was deposited to Wasabi, a privacy-focused exchange, and 200 Ethereum (ETH) was sent to Tornado Cash, a mixing service, as of August 4, 2026. This minimal laundering activity suggests the attackers may be multiple individuals or groups still figuring out how to move such a large sum without triggering regulatory scrutiny. In contrast, professional crypto hackers like those linked to North Korea often begin aggressively laundering stolen funds within hours or days.

Interestingly, on-chain analysis also revealed spam messages in the Bitcoin transaction data offering to launder the stolen funds in exchange for a 7 percent fee. While this could have been an opportunistic scammer trying to defraud the hackers themselves, it illustrates how quickly illicit service providers seek to capitalize on major security incidents by advertising money laundering services directly on the blockchain.

The true scale of the Coldcard exploit will likely take time to emerge. Funds are still moving, and victims often come forward over months or years as thefts are noticed. TRM Labs, the blockchain intelligence firm that published the analysis, treats the current figures as preliminary rather than final. Because transaction patterns point to multiple attackers, TRM has not attributed the theft to a specific actor at this stage. What is clear, however, is that a five-year-old firmware bug has become one of 2026's costliest security breaches, affecting thousands of users who believed their Bitcoin was safe in cold storage.