According to a report by CoinDesk, Galaxy Research has tracked three waves of thefts targeting addresses generated by Coldcard hardware wallets. As of August 2, 2026, the observed total stood at 1,367.05 BTC, worth roughly $88.6 million, taken from 4,585 addresses. Galaxy has described the exploit as ongoing.
While the incident has attracted attention across the crypto community, it is important to understand what it actually means for Bitcoin holders. It does not mean that every Bitcoin cold wallet is vulnerable. Instead, the incident highlights the importance of secure key generation, trusted wallet technology, and responsible storage practices.
What happened in the recent attack?
The vulnerability traces to a firmware release from March 2021, specifically version 4.0.1 of the Coldcard Mk3 firmware, made by Canadian manufacturer Coinkite. That build mistakenly routed seed phrase generation to a software-based pseudorandom number generator instead of the device’s dedicated hardware random number generator.
The practical consequence is significant. A software randomizer produces a predictable, bounded range of possible outputs. According to an analysis published by Block, an attacker who can determine or sufficiently constrain the device identifier, timer state, and prior random-number-call history can reproduce candidate key streams offline, without ever needing physical access to a device.
Galaxy Research has mapped the resulting thefts across three waves:
- Wave 1 (July 30, 2026): roughly 1,082.65 BTC about $70.2 million at the time drained from 1,196 addresses in approximately 41 minutes.
- Wave 2 (August 1, 2026): the running total rose to 1,158.66 BTC, around $75.1 million, across 2,673 addresses.
- Wave 3 (August 2, 2026): approximately 208 BTC swept from a further 1,912 addresses, bringing the observed total to 1,367.05 BTC across 4,585 addresses.
Galaxy has said it believes each wave was internally the work of a single operator but has cautioned against assuming the same attacker is behind all three. The firm has reported approximately 600 suspected attacker-controlled addresses to federal investigators, compliance firms, and cross-industry cybersecurity researchers.
One detail worth noting: the stolen coins had reportedly sat dormant for an average of 3.18 years before being swept. That suggests the victims were largely long-term holders and that the attacker had pre-computed a large set of vulnerable keys rather than reacting to live wallet activity.
Galaxy has also been transparent about the limits of its work, noting that its findings are based on on-chain analysis and that it has not computationally confirmed that every identified address was generated using weak Coldcard entropy.
Private keys are fundamental to Bitcoin ownership because they authorize transactions. If a private key can be discovered or reproduced, an attacker may be able to access the Bitcoin associated with it. This explains why the security of a Bitcoin cold wallet depends not only on keeping the device offline but also on the technology used to generate its keys.
Updating firmware alone does not fix these Bitcoin cold wallet attacks
This is the single most important point for affected users, and it is easily misunderstood.
Coinkite issued a security advisory and released patched firmware by August 1, 2026, which prevents the problem from affecting newly created wallets. However, installing the update does not protect anyone who already generated a recovery phrase on the affected firmware. Those keys were already created from a weak source of randomness, and no subsequent update can change that.
Coinkite has advised users whose seeds were generated on affected firmware versions to migrate their funds to newly generated seeds, unless they either supplemented the wallet’s entropy with an independent source or used a strong BIP-39 passphrase.
Galaxy Research has urged anyone holding single-signature funds on Coldcard-generated addresses to move them immediately, and has warned that vulnerable wallets are likely to be emptied eventually. Users who are uncertain whether their device or firmware version is affected should consult Coinkite’s official advisory directly rather than relying on secondary sources.
Does this mean Bitcoin cold wallets are unsafe?
No. The incident should not be interpreted as a problem affecting every Bitcoin cold wallet or as a reason for investors to abandon Bitcoin. It relates to a specific firmware build from a specific manufacturer, released more than five years ago. It does, however, demonstrate that security involves multiple layers and that a single implementation error in one of those layers can undermine the rest.
Cold storage remains a widely used option for people who want to hold Bitcoin for longer periods while reducing exposure to internet-based threats. The important factors are choosing a reputable wallet, keeping firmware current, and following recommended security practices.
A Bitcoin cold wallet should therefore be viewed as an important security tool rather than a guarantee against every possible risk.
How can Bitcoin holders protect their assets?
- Follow official manufacturer guidance. Anyone using a Bitcoin cold wallet should follow the official security and setup instructions provided by the wallet manufacturer and should actively monitor firmware updates and security advisories relevant to their specific device and model.
- Treat recovery phrases as highly sensitive. Private keys and recovery phrases should never be shared with anyone, photographed, stored in cloud services, or entered into unknown websites, applications, or online forms.
- Consider a BIP-39 passphrase. In this incident, wallets protected by a strong passphrase were reportedly not exposed in the same way, because the passphrase adds a secret that sits outside the compromised key generation process.
- Consider multisignature storage for larger holdings. Galaxy’s warning was directed specifically at holders of single-signature funds. Multisignature setups require multiple independent keys to authorize a transaction, which means the compromise of one key alone is not sufficient to move funds. For investors holding significant amounts, this is worth evaluating.
- Supplement entropy where the device allows it. Some hardware wallets permit users to contribute additional randomness during setup, for example, through dice rolls. This reduces reliance on the device’s own random number generation.
- Migrate rather than assume. If there is any reasonable doubt about how a seed was generated, generating a fresh seed on current, patched firmware and moving funds is the conservative course of action.
Why does cold storage still matter?
The recent incident does not change the fundamental purpose of a Bitcoin cold wallet. By keeping private keys away from everyday online activity, cold storage can reduce exposure to several common digital threats, including malware, phishing, and exchange compromises.
The key takeaway is that cold storage works best when combined with strong security practices across the entire lifecycle from key generation and wallet setup through to recovery phrase storage and firmware updates. This attack succeeded at the very first step of that chain, which is why keeping the device offline offered no protection.
As cryptocurrency technology continues to develop, security practices will evolve alongside it. Incidents like this help wallet developers, security researchers, and users identify potential weaknesses and strengthen the systems protecting digital assets.
For Bitcoin investors, the message is not to avoid Bitcoin or cold wallets. It is to understand the technology, choose trusted solutions, keep software current, and stay informed about advisories affecting the devices they rely on.
A properly managed Bitcoin cold wallet can remain a valuable option for long-term Bitcoin storage, giving users greater control over their assets while reducing exposure to many online risks. The latest incident simply reinforces an important principle of crypto security: protecting your Bitcoin is not only about where you store it, but also about how securely the keys were created in the first place.