Coldcard Hack Tracker: Live Timeline & Stolen Funds
By Ben — I've been in Bitcoin since 2013 and have followed this exploit from its first hours; people in our community were affected. Here is what we know, kept current as the situation develops.
~1,816 BTC
stolen (~$116M)
5,200+
addresses affected
15+
separate attackers
Last updated: August 4, 2026
Figures from Galaxy Research and on-chain analysis; updated as new waves are confirmed.
What happened
The root cause is an implementation flaw, not a Bitcoin protocol flaw. A Coldcard firmware build released in March 2021 routed seed generation through a weak pseudo-random number generator instead of the device's true hardware RNG. Seeds that should have been drawn from an effectively infinite space became predictable — and reproducible offline by anyone who understood the flaw. Attackers regenerated those seeds at scale, derived the corresponding addresses, and swept whatever they held. Every drained wallet traces back to a seed created on affected firmware after March 17, 2021. Bitcoin itself worked exactly as designed throughout: whoever holds the keys spends the coins. The failure was that the keys were never as random as their owners believed.
Timeline
Jul 30, 2026 · 01:10–01:51 UTC
Wave 1 — the initial drain
1,082.65 BTC drained from 1,196 addresses in just 41 minutes, across 9 blocks. The attacker worked methodically from the largest balances down — roughly $30M moved in the first 10 minutes.
Jul 30, 2026 · ~22:50 UTC
Coinkite publishes its first advisory
Roughly 30 hours after the attack began, Coinkite issued its first public advisory — initially focused on the older Mk3 model.
Aug 1, 2026
Wave 2 — newer models confirmed affected
The running total rises to 1,158.66 BTC (~$75M) drained from 2,673 addresses. A security researcher confirms that Mk4, Mk5 and Q devices are also being drained — this is not limited to older models.
Aug 2, 2026
Wave 3 — a second attacker appears
The total reaches 1,367 BTC (~$89M) from 4,585 addresses. A distinctly different on-chain pattern suggests at least a second, independent attacker is now exploiting the same weakness.
Aug 3–4, 2026
Wave 4 — a feeding frenzy
The total climbs to ~1,816 BTC (~$116M) drained from more than 5,200 addresses. On-chain analysis now attributes the thefts to at least 15 separate attackers racing to sweep vulnerable wallets before their owners do.
Key facts
- ▸Affected: any seed generated on affected firmware after March 17, 2021, without a passphrase or user-added extra entropy.
- ▸All Coldcard models — Mk2, Mk3, Mk4, Mk5 and Q — are confirmed affected.
- ▸The stolen funds remain unspent and traceable on-chain; Galaxy has reported roughly 600 attacker addresses to federal investigators.
- ▸A BIP39 passphrase (the “25th word”) protected users even when their underlying seed was vulnerable.
What to do if you have a Coldcard
- 1.Check when your seed was generated. If the wallet was set up after March 17, 2021 and you did not use a passphrase or add your own entropy (dice rolls), assume the seed is compromised.
- 2.Do not wait for confirmation. Attackers are sweeping vulnerable wallets faster than advisories are updating.
- 3.Migrate now: update to patched firmware, generate a completely fresh seed, and move your funds to it. A new seed on old firmware solves nothing.
- 4.Going forward, add a passphrase to any new setup — it is the single cheapest layer of protection this incident has vindicated.
Full walkthrough: Was Your Coldcard Affected? How to Check and What to Do. Our guides on the BIP39 passphrase and getting started with self-custody cover the fundamentals of doing this safely.
Related reading
This page is an editorial reference compiled from public reporting and on-chain data, and is updated manually as new information is confirmed. Figures are estimates and may be revised. Nothing here is financial advice.