Losses from a critical security flaw in Coldcard hardware wallets now exceed $115 million, according to freshly compiled data from Galaxy Research. That figure, based on victim addresses identified through August 13, is still rising, turning a five year old firmware bug into one of the largest single self custody failures in crypto history.

Coldcard's $115 Million Security Breach Shatters Bitcoin Vault Myth
XOOMAR Intelligence
Analyst Take
The research firm posted its calculations on X Sunday (Aug. 16) according to PYMNTS, noting it has engaged with over 200 victims directly. Galaxy stated these conversations aim both "to support them and gather intelligence on the attackers." This signals a transition from observation to active investigation, though the stolen funds remain largely off limits on the blockchain.
Analysts at firms like Twenty-One Million note some trackers place losses above $130 million. The breach exploited a vulnerability affecting older firmware on Coldcard Mk3, Mk4, Mk5, and Q devices sold by manufacturer Coinkite. The flaw weakened the entropy, or randomness, used to generate wallet recovery seeds, making them predictable enough for attackers to reconstruct private keys and drain assets without ever touching the physical device. A five year window of vulnerability meant thousands of wallets, many held by long term bitcoiners, were silently at risk.
The Pillar of "Cold Storage" Cracks
The shock lies not in the target but in its reputation. Coldcard is marketed as the austere, air gapped fortress for bitcoin. Its primary draw is being offline, or "cold," theoretically immune to remote hackers. This breach circumvented that entire premise. An attacker didn't need to phish a user, intercept a shipment, or install malware. They simply needed to reverse engineer seeds created on flawed firmware, a task made possible by a human engineering error that substituted predictable device data for true hardware randomness.
The breach systematically punctures the industry's most sacred security promise: that absolute control over private keys equals absolute safety. As one analyst told PYMNTS, "A device disconnected from the internet can still generate a vulnerable key... Assets can still disappear without the device ever leaving a safe."
This incident echoes, on a far larger scale, the fundamental threat outlined in our prior coverage of a Shipping Data Breach Turns Crypto Wallets Into Physical Targets. Both scenarios prove that hardware security is a chain, and its weakest link may be utterly invisible to the end user.
Who was hit? The data points to technically savvy, long term holders who thought they had done everything right. One Canadian entrepreneur, Jonathan Goodman, lost roughly C$1.6 million ($1.2M USD) from bitcoin stored on a Coldcard in a bank safety deposit box. His plaintive post on X resonated: "Perhaps the hardest part about this is that I did everything right. I never shared my seed phrase with anybody. My devices never touched the internet."
This isn't just about lost money, it's about a broken trust model for a core segment of the crypto market.
Manufacturers Face a New Bar for "Security"
The immediate technical response from Coinkite has been a rapid firmware patch and directives for users to generate entirely new seeds. But the aftershocks are forcing a hardware wide reckoning.
The Open Source Audit Paradox
Coldcard’s firmware is open source, a feature long touted for enabling community audits. This bug, however, sat undetected for five years. As one analysis cited by PYMNTS notes, “Open-source software can still contain a flaw… 'open source' catches problems eventually, not instantly.” The implication is stark: transparency alone is not a real time shield. It requires constant, expert review, which failed here.
XOOMAR Analysis: Coinkite CEO Rodolfo Novak hypothesized that "AI assisted code review" may now be finding latent bugs faster than human experts, a suggestion that has been controversial among security specialists who label this a straightforward human error. Regardless of the root cause, the outcome pressures all hardware wallet makers to justify their firmware development and auditing lifecycle with new rigor.
A Catalyst for Complex Custody?
For institutional players, this breach is a marketing gift wrapped in a tragedy. It validates their core pitch: that professional, multi signature custody solutions with layered operational controls can mitigate single points of failure like a firmware bug. For retail, it may push adoption of more complex but resilient practices:
- Manual entropy generation, like using dice rolls to create a seed, which was unaffected by this bug.
- Multisignature vaults, which require multiple keys to authorize a transaction.
- Strong passphrases, which add an extra layer of security even if a seed is compromised.
The question is whether users will embrace this complexity or retreat from self custody altogether.
What Comes Next: Tracking, Not Recovery
For the over 200 confirmed victims, the path forward is bleakly clear.
Galaxy Research indicates about 90% of the stolen bitcoin remains unmoved in traceable wallets. This creates a slim possibility for recovery through law enforcement and exchange blacklists, but it’s a long shot. The funds are cryptographically controlled by the attacker. The primary hope is that the publicity and blockchain forensics make the coins too toxic to cash out.
The broader industry watchlist now has two new items:
- The final loss tally. With attacks described as "still ongoing," the $115 million figure is a snapshot. It will likely grow as more vulnerable addresses are identified and swept.
- Competitive response. How will rival hardware wallet firms like Ledger or Trezor communicate their security architecture in the wake of this? Expect renewed emphasis on their specific entropy sources and external audit reports. This event could function as a brutal stress test for the entire product category's marketing claims.
This breach proves that the most critical vulnerabilities exist not on the blockchain, but in the silicon and code that are supposed to guard it. As we've seen in other sectors facing existential technological threats, like the need for post quantum cryptography, foundational security assumptions must be constantly challenged. For bitcoiners, the sacred hardware wallet must now be viewed not as a vault, but as a complex system that can fail. The era of blind faith in a single device is over.
The Bottom Line
- A critical flaw in highly trusted "cold storage" hardware has led to one of the largest self-custody failures in crypto.
- The breach undermined the core security premise of air-gapped devices by allowing remote, offline private key reconstruction.
- The vulnerability affected products sold over a five-year window, placing thousands of long-term bitcoin holders at risk well after purchase.
Reported Losses from Coldcard Breach
Sources
Written by
XOOMAR Insights Team
Research and Editorial Desk
The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.
Explore More Topics
Related Articles
CybersecurityColdcard Hack Voids $100 Million Self-Custody Promise
A flaw in Coldcard hardware wallets let attackers drain over $100 million, proving that even air-gapped devices can betray users and forcing a brutal risk reass
CybersecurityHackers Drain $130M from Offline Crypto Wallets
Hackers stole over $130 million in Bitcoin by exploiting a firmware bug in Coldcard hardware wallets, attacking devices that were supposedly secure because they
CybersecurityA Crypto Wallet's Secret Leak Was Right on the Label
Trezor's promise of 'your keys, your coins' was undercut by a leak at its logistics partner, exposing thousands of customers' personal shipping details and reve
CybersecurityShipping Data Breach Turns Crypto Wallets Into Physical Targets
Cryptocurrency holders who bought hardware wallets for security are now targeted for physical theft after their personal information was stolen from the shippin
CybersecurityInsider Demands $7,540 For Cache Of Corporate Secrets
A data analyst contractor was sentenced to two years in prison for stealing employee data and trying to extort $2.5 million, but the company paid just $7,540 to
TradingBitcoin Giants Buy the Math, Never the Price
The world's two biggest public BTC holders, Strategy and Metaplanet, are ignoring price to accumulate a fixed asset against an expanding money supply, betting o
TradingBitcoin Slides As Trap in July CPI Data Emerges
A market analyst argues July's cooler CPI reading is a head-fake, hiding stubborn underlying inflation that's rattling Bitcoin and could keep the Fed hawkish.
FintechGoldman Sachs Declares September Fed Rate Hike Unlikely
Goldman Sachs delivered a blunt verdict to markets, declaring a September Fed interest rate hike is very unlikely due to a softening economy, a call that immedi
TechnologyAmazon Bulldozes Rare Books for AI-Fueled Data War
Amazon is buying and then destroying rare books in a Las Vegas warehouse to scan their pages and feed text data into its AI training models, a practice uncovere
Global TrendsRural Fury Forces Government Housing Retreat
Facing a quantified backlash and stark political math, ministers have scrapped a key reform that would have let developers pay cash instead of building affordab
Don't miss the signal
Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.
Free forever. No spam. Unsubscribe anytime.