Key Takeaways
- Attackers exploited a firmware vulnerability dating back to March 2021 to steal more than 1,778 Bitcoin from Coldcard hardware wallets
- Total verified losses exceed $112.7 million, affecting over 8,600 wallet addresses
- Galaxy Research indicates hackers likely leveraged unrestricted artificial intelligence systems to identify and weaponize the security flaw
- Defensive security teams claim AI safety regulations at major US laboratories prevented them from deploying comparable tools for protection
- Multisignature wallets remained secure throughout the attack; all affected users should immediately create fresh seed phrases
An undetected security vulnerability embedded within Coldcard firmware since March 2021 enabled cybercriminals to extract more than 1,778 Bitcoin from in excess of 8,600 wallet addresses, establishing this incident as the most significant hardware wallet compromise ever documented. Based on prevailing market values, verified financial damages reach $112.7 million.
The coordinated assault commenced on July 30, 2026. During an intensive 41-minute window, attackers drained over 1,000 Bitcoin from more than 1,000 separate addresses. Since August 6, no additional malicious transactions have been detected.
The underlying cause originated from a firmware modification released by Coinkite in version 4.0.1. This particular update inadvertently redirected the seed phrase creation mechanism away from a hardware random number generator toward a software-based pseudorandom number generator. Software-driven randomness demonstrates significantly greater predictability, substantially simplifying the process of guessing or recreating the generated cryptographic keys.
According to reports, a developer brought a connected concern to Coinkite’s attention as early as May 2025. The security weakness remained unaddressed for sufficient time to allow malicious actors to construct and execute exploitation frameworks at scale targeting multiple Coldcard hardware versions, including Mk2, Mk3, Mk4, Q, and Mk5 models.
Artificial Intelligence Utilized by Attackers and Defenders
Galaxy Research concluded with substantial certainty that numerous attackers employed artificial intelligence systems lacking cybersecurity safeguards to locate and weaponize the vulnerability. The recently launched open-source Kimi K3 platform was cited as representative of the technology type presumably deployed.
Rob Hamilton, who leads Anchorwatch as chief executive, stated that security protocols implemented at prominent US AI research facilities substantially restricted security professionals from utilizing equivalent defensive technologies. He noted this limitation forced defensive teams to depend on identical Chinese open-source platforms employed by hostile actors.
Hamilton joined approximately 25 additional experts, including developer James O’Beirne and Calle from the Cashu initiative, to establish what they designate as the Bitcoin Red Team. This collective has been systematically examining code repositories throughout the ecosystem to identify security weaknesses and propose remediation measures.
Coinkite published a security bulletin on July 30 and distributed corrected firmware by July 31. CEO Rodolfo Novak released a public statement of apology.
Critical Actions Required for Affected Users
Installing updated firmware alone fails to resolve the underlying security problem. Any seed phrase created using compromised firmware versions remains permanently vulnerable. Users must generate an entirely new seed phrase utilizing patched firmware and transfer all assets to newly created wallets.
Among the 1,778 Bitcoin verified as stolen, 1,531 Bitcoin continues to sit idle within attacker-controlled addresses. Approximately 246 Bitcoin has been relocated, with 65% entering Coinjoin privacy-enhancing transactions and 35% transferred through on-chain methodologies intended to conceal transaction paths.
Remarkably, multisignature wallet configurations experienced zero theft incidents. Multisig architectures demand multiple private keys to validate transactions, ensuring that a single compromised seed phrase cannot facilitate unauthorized fund movement.
Galaxy reports distributing attacker wallet address information to cryptocurrency exchanges, regulatory compliance organizations, and law enforcement authorities, anticipating potential asset freezing should funds reach centralized service providers.
This theft event occupies the twentieth position among all documented cryptocurrency thefts, positioned beneath Multichain’s $130 million loss during July 2023 and exceeding the $100 million extracted from Harmony’s Horizon bridge during June 2022.





