Coldcard Hack Rises to Third-Largest Crypto Attack: What On-Chain Forensics Reveal

A lifelike Bitcoin coin with intricate engravings is spotlighted amid glowing data panels and a cinematic, hazy background.
  • The Coldcard hack is now ranked the third-largest crypto hack of 2026 by TRM Labs.
  • Loss estimates diverge: TRM puts losses at 1,816 BTC, Galaxy Research at up to 2,055 BTC as of early August.
  • Forensics show roughly 90% of stolen bitcoin remains unmoved, with evidence pointing to multiple attackers.
  • Coinkite has released patched firmware and migration guidance, but trust in Bitcoin self-custody is shaken.
  • Cybersecurity stocks rallied, while BTC/ETH prices stayed stable after the Coldcard hack news.

Coldcard Hack Status Update: Third-Largest Crypto Hack of 2026

The Coldcard hack has now been classified as the third-largest crypto hack of 2026 by TRM Labs, as of August 6, 2026 (TRM Labs' analysis of the Coldcard hack). TRM estimates that 1,816 BTC—approximately $116 million—were drained from more than 5,200 Bitcoin addresses in a series of four coordinated attack waves. Galaxy Research, however, reports a slightly different picture: their tracking found 1,596 BTC stolen from about 7,300 addresses, with a potential fourth wave that could bring the total to 2,055 BTC, estimating losses between $130 million and $132 million as of August 5, 2026 (Galaxy Research's competing loss estimate). The incident remains under active investigation, with the full scope of the breach and precise address count still subject to forensic review.

Source: TRM Labs, Aug 6, 2026

How a 2021 Build Flaw Broke Coldcard's Randomness

The vulnerability at the heart of the Coldcard hack traces back to a build configuration error introduced in a March 2021 firmware update for the Coinkite hardware wallet. Instead of using the device's hardware random number generator (RNG), the firmware silently defaulted to MicroPython's built-in software pseudo-RNG, which is far less secure (Coinkite's technical breakdown of the entropy issue). In cryptography, "entropy" is a measure of how unpredictable a random value is—think of it as the difference between a truly random dice roll and a computer-generated "random" number that could be guessed.

This flaw slashed the effective entropy in generated seed phrases (the secret words that unlock your wallet): Mk3 Coldcard devices dropped to about 40 bits of entropy, while Mk4/Mk5/Q models managed only 72 bits, compared to the intended 128-bit security target (as of July 31, 2026, per Coinkite). For context, 128-bit entropy is like trying to guess a specific grain of sand from the Sahara; 40 or 72 bits is more like picking the right marble from a bag of a few trillion. Notably, wallets created using at least 50 physical dice rolls or protected by a strong BIP-39 passphrase were not considered at risk from this RNG flaw alone (Coinkite's official security advisory).

Timeline: From the First 30-Minute Sweep to Four Waves

The Coldcard hack campaign began on July 30, 2026, when attackers executed an initial sweep, draining funds from compromised wallets in under 30 minutes, according to TRM Labs and earlier Coldcard wallet hack update. Coinkite issued a public advisory that same week, warning users of the vulnerability. Over the following days, three more waves of theft targeted additional addresses, culminating in a suspected fourth wave as reported by Galaxy Research and covered in the fourth wave of the Coldcard hack update.

DateMilestoneSource
2026-07-30First attack wave drains funds in 30 minutesTRM Labs
2026-07-31Coinkite issues security advisoryCoinkite
2026-08-02Second and third attack waves identifiedGalaxy Research
2026-08-05Suspected fourth wave reportedGalaxy Research
2026-08-06TRM Labs ranks Coldcard hack third-largest in 2026TRM Labs

Both TRM Labs and Bloomberg provided detailed breakdowns on August 5-6, 2026, confirming the evolving scale of the breach and the expanding list of affected wallets.

Where the Stolen Bitcoin Is Sitting Now

Forensic blockchain analysis by TRM Labs shows that, as of August 6, 2026, nearly 90% of the bitcoin stolen in the Coldcard hack remains unmoved in attacker-controlled addresses (TRM Labs' analysis of the Coldcard hack). There has been minimal evidence of laundering—no layering, mixing, or attempts to cash out on-chain. This lack of movement is unusual for a major hardware wallet vulnerability, where attackers often use mixing services or rapid "peeling" transactions to try to obscure the source of stolen coins.

Interestingly, forensic analysts detected differences in how transactions were constructed across the four attack waves, suggesting that multiple attackers or groups could be involved. However, TRM Labs has not attributed the theft to any specific actor or group as of this writing. The on-chain forensics community continues to monitor these addresses for any sign of laundering or attempts to liquidate the stolen bitcoins.

Source: TRM Labs, Aug 6, 2026

Coinkite's Response: Patched Firmware and an AI Blind Spot

Coinkite, the maker of the Coldcard hardware wallet, said it was unaware of the bug until the recent disclosure. Even a recent internal review using "one of the best available AI models" to scan firmware code failed to detect the flaw or any other serious vulnerability, as admitted by the company (Coinkite's technical breakdown of the entropy issue; Coinkite's admission that AI missed the flaw). This blind spot for AI code review tools has prompted renewed debate on the reliability of automated security analysis in cold storage security.

To address the vulnerability, Coinkite released fixed firmware—version 4.2.0 for Mk2 and Mk3 devices, with updated releases for Mk4, Mk5, and Q models. Users who cannot confirm they used at least 50 dice rolls (adding enough entropy) or a strong BIP-39 passphrase are advised to migrate their funds to a new wallet generated using the patched firmware (Coinkite's official security advisory). This is a reminder that firmware patches alone cannot repair already-generated weak seeds; proactive migration is essential. For a broader industry context, see CoinGabbar's coverage of the volunteer Bitcoin red team audit response triggered by the Coldcard hack.

How This Compares to 2026's Other Big Crypto Hacks

The Coldcard hack pushed 2026’s cumulative crypto hack total above $1.2 billion across 276 incidents, according to the latest TRM Labs report as of August 6, 2026 (TRM Labs' analysis of the Coldcard hack). By this measure, the Coldcard event now ranks just behind the year's two largest breaches. Meanwhile, Blockaid, a blockchain security firm, tallied $1.1 billion lost in the first half of 2026 alone, across 212 on-chain exploits. The difference in totals stems from Blockaid’s half-year reporting window, while TRM’s figure is year-to-date and includes additional incidents (Blockaid's H1 2026 hack report).

CoinGabbar previously reported on Coldcard hack losses hitting $130M and the regional distribution of affected holders. Comparing incident counts and loss amounts is complicated by differences in classification: some trackers count only "on-chain" exploits, while others include off-chain and wallet-specific attacks. The Coldcard hack’s unique hardware wallet vulnerability sets it apart from protocol-level exploits.

TrackerCoverage PeriodLossesIncidents
TRM LabsYTD 2026$1.2 billion276
BlockaidH1 2026$1.1 billion212

Market and Trust Fallout

The market reaction to the Coldcard hack has been mixed. Cybersecurity-focused ETFs rallied: the First Trust NASDAQ Cybersecurity ETF (CIBR) gained about 7% and the Global X Cybersecurity ETF (BUG) rose nearly 8% since the hack update, reportedly according to Benzinga on August 5, 2026 (cybersecurity ETF reaction to the hack). It is unclear if the correlation is causal, but the timing has put cybersecurity stocks on more investors' radar.

In contrast, Bitcoin and Ethereum prices saw less than a 1% drop in the days following the Coldcard hack disclosure, per Fortune’s August 3, 2026 reporting. This suggests the broader market has largely absorbed the shock, at least for now. However, the reputational impact among individual users has been more severe. Bloomberg highlighted the story of Tim Lamb, a Bitcoin holder forced to consider cutting his vacation short to check his funds (Bloomberg's report on eroded trust after the hack). Canadian holder Jonathan Goodman said the incident shattered his confidence in both Bitcoin and cold wallets, vowing to step back from further investment.

As TRM Labs’ Ari Redbord put it, the Coldcard hack demonstrates that Bitcoin self-custody risk does not disappear; it simply shifts to the user and the technology. This hardware wallet vulnerability has forced a reckoning not only for Coinkite but for the entire cold storage security landscape.

What Coldcard Owners Should Watch Next

For Coldcard hardware wallet owners, the immediate priority is to check whether their wallet was initialized with at least 50 dice rolls or a strong BIP-39 passphrase. If not, migration to a newly generated seed using the latest patched firmware is advised. Independent cross-verification of the total loss figure came from Elliptic’s Tom Robinson, who told TechCrunch that TRM’s $130 million estimate was roughly correct as of August 4, 2026.

However, unresolved questions remain: What will the final confirmed loss total be? Who, exactly, is behind the Coldcard hack? As of now, TRM Labs has not attributed the theft to any specific actor. Owners should monitor official advisories, forensic updates, and reputable industry sources for further developments. For those seeking to confirm their own wallet’s safety, follow Coinkite’s published migration steps and consider seeking independent security advice.

For a detailed breakdown of how much Bitcoin was stolen in the Coldcard hack and what to do next, see the earlier sections and stay tuned for further TRM Labs report updates.

Sourabh Agrawal

About the Author Sourabh Agrawal

English News Writer at coingabbar.com

Sourabh Agarwal, a Chartered Accountant and co-founder of Coin Gabbar, has covered crypto markets, blockchain policy, and digital-asset regulation since 2021, following a decade of equity, commodity, and macro research on brokerage desks. He writes news, scenario-based price outlooks, and long-form explainers — sources named, assumptions stated, risks disclosed. His analysis is published for information purposes and is not investment advice.

Leave a comment

Frequently Asked Questions (FAQ)

Faq Got any doubts? Get In Touch With Us