On July 30, 2026, hackers drained 1,367 BTC, valued at about $88.6 million, from wallets linked to Coldcard Mk3 devices. This massive theft unfolded in three waves, targeting 4,585 wallets vulnerable due to a firmware glitch.
The biggest hit struck in just 41 minutes, when 1,082 BTC vanished in a single coordinated sweep. Galaxy Research’s deep dive revealed that early waves had identical transaction patterns and fixed fees, hinting at a single attacker or toolkit behind the onslaught. The third wave differed, suggesting either a new player or a change in tactics. Most stolen coins remain parked in few attacker-controlled addresses.
The root cause lies in a flaw present since March 2021 in Coldcard Mk3 firmware version 4.0.1 and later. Its random number generator produced predictable wallet seeds. This weakness let attackers enumerate possible seeds offline, match them to real blockchain addresses, and move funds without needing physical access to the hardware wallets.
Block’s engineers first flagged the random number generator problem. Coinkite, Coldcard’s maker, issued a security advisory about 30 hours after the thefts started. Newer Coldcard models like Mk4, Q, and Mk5 are unaffected. Users with funds on compromised Mk3 wallets are urged to create new seeds on updated devices immediately.
This incident more than doubled initial estimates of 594 BTC lost, exposing a far wider breach than first thought. It shows risks even with hardware wallets, often seen as the safest option. Recent reports show some stolen coins are now moving into exchanges, raising concerns about laundering.
This content is informational and not financial advice.



