A significant security breach involving Coldcard hardware wallets has led to the theft of nearly $130 million in Bitcoin, as attackers exploited a vulnerability to drain about 2,100 BTC over several attack phases. This incident, identified in late July, represents one of the largest hardware wallet security failures in recent Bitcoin history, prompting widespread fund transfers and heightened vigilance around wallet security measures.
What Happened to Coldcard Devices?
The issue affected Coldcard wallets, offline devices crafted by the Canadian firm Coinkite, known for their robust security and self-custody features. Onchain research unearthed that the breach was due to a firmware flaw dating back to March 2021. This bug allowed private keys to be generated through an inadequate software random number generator, circumventing the more secure hardware component. This vulnerability drastically reduced the private key’s security, making wallets susceptible to key-guessing attacks.
Perpetrators targeted these wallets systematically, seizing Bitcoin from susceptible addresses. Galaxy Research’s findings reveal three major attack phases, with at least 1,596 BTC appropriated from over 5,200 wallets. Some estimates suggest the total BTC stolen may be closer to 2,100.
How Did Bitcoin Holders React?
Following the breach, onchain analytics from platforms like Checkonchain and Glassnode noted a swift exodus of Bitcoin. Approximately 233,000 BTC, valued at around $15 billion at current market prices, were moved out of long-term storage within days, highlighting a reevaluation of self-custody practices.
Casa’s CEO Nick Neuman stated that many transfers were from not just Coldcard users but also those using similar hardware wallets such as Ledger and Trezor. These users, prompted by the breach, upgraded their security measures, adopting multisignature solutions for enhanced protection against similar threats.
- The Coldcard breach saw approximately 2,100 BTC stolen.
- Following the breach, 22,000 BTC were moved to exchanges.
- Bitcoin transferred from long-term holders amounted to 233,000 BTC, marking a 1.38% dip in holder supply.
- This event caused the most significant weekly reduction in long-term holder supply since December 2024.
Broader Implications for Bitcoin Security
The breach highlighted the critical role of self-custody in the security of digital assets. Unlike centralized exchange hacks, where losses can be immediate and total, the gradual nature of this theft allowed many to secure their Bitcoin before it could be taken.
“The onchain metrics around the Coldcard incident reinforce how important self-custody is to the resilience of Bitcoin as an asset class,” commented Casa CEO Nick Neuman on X.
Neuman emphasized that the swift movement of possibly affected funds signifies a robust self-custody network capable of responding to threats. The incident has sparked discussions on maintaining and improving hardware wallet standards, protocols, and user awareness to prevent recurrence.



















English (US)