Live Tracker

Coldcard Hack Tracker: Live Timeline & Stolen Funds

By Ben — I've been in Bitcoin since 2013 and have followed this exploit from its first hours; people in our community were affected. Here is what we know, kept current as the situation develops.

~1,816 BTC

stolen (~$116M)

5,200+

addresses affected

15+

separate attackers

Last updated: August 4, 2026

Figures from Galaxy Research and on-chain analysis; updated as new waves are confirmed.

What happened

The root cause is an implementation flaw, not a Bitcoin protocol flaw. A Coldcard firmware build released in March 2021 routed seed generation through a weak pseudo-random number generator instead of the device's true hardware RNG. Seeds that should have been drawn from an effectively infinite space became predictable — and reproducible offline by anyone who understood the flaw. Attackers regenerated those seeds at scale, derived the corresponding addresses, and swept whatever they held. Every drained wallet traces back to a seed created on affected firmware after March 17, 2021. Bitcoin itself worked exactly as designed throughout: whoever holds the keys spends the coins. The failure was that the keys were never as random as their owners believed.

Timeline

  1. Jul 30, 2026 · 01:10–01:51 UTC

    Wave 1 — the initial drain

    1,082.65 BTC drained from 1,196 addresses in just 41 minutes, across 9 blocks. The attacker worked methodically from the largest balances down — roughly $30M moved in the first 10 minutes.

  2. Jul 30, 2026 · ~22:50 UTC

    Coinkite publishes its first advisory

    Roughly 30 hours after the attack began, Coinkite issued its first public advisory — initially focused on the older Mk3 model.

  3. Aug 1, 2026

    Wave 2 — newer models confirmed affected

    The running total rises to 1,158.66 BTC (~$75M) drained from 2,673 addresses. A security researcher confirms that Mk4, Mk5 and Q devices are also being drained — this is not limited to older models.

  4. Aug 2, 2026

    Wave 3 — a second attacker appears

    The total reaches 1,367 BTC (~$89M) from 4,585 addresses. A distinctly different on-chain pattern suggests at least a second, independent attacker is now exploiting the same weakness.

  5. Aug 3–4, 2026

    Wave 4 — a feeding frenzy

    The total climbs to ~1,816 BTC (~$116M) drained from more than 5,200 addresses. On-chain analysis now attributes the thefts to at least 15 separate attackers racing to sweep vulnerable wallets before their owners do.

Key facts

  • Affected: any seed generated on affected firmware after March 17, 2021, without a passphrase or user-added extra entropy.
  • All Coldcard models — Mk2, Mk3, Mk4, Mk5 and Q — are confirmed affected.
  • The stolen funds remain unspent and traceable on-chain; Galaxy has reported roughly 600 attacker addresses to federal investigators.
  • A BIP39 passphrase (the “25th word”) protected users even when their underlying seed was vulnerable.

What to do if you have a Coldcard

  1. 1.Check when your seed was generated. If the wallet was set up after March 17, 2021 and you did not use a passphrase or add your own entropy (dice rolls), assume the seed is compromised.
  2. 2.Do not wait for confirmation. Attackers are sweeping vulnerable wallets faster than advisories are updating.
  3. 3.Migrate now: update to patched firmware, generate a completely fresh seed, and move your funds to it. A new seed on old firmware solves nothing.
  4. 4.Going forward, add a passphrase to any new setup — it is the single cheapest layer of protection this incident has vindicated.

Full walkthrough: Was Your Coldcard Affected? How to Check and What to Do. Our guides on the BIP39 passphrase and getting started with self-custody cover the fundamentals of doing this safely.

Related reading

This page is an editorial reference compiled from public reporting and on-chain data, and is updated manually as new information is confirmed. Figures are estimates and may be revised. Nothing here is financial advice.