SecurityAugust 6, 2026

Coldcard theft rises to 1,816 bitcoin across 5,200 addresses

TRM Labs now counts roughly 1,816 bitcoin, some 116 million dollars (about €101.5 million), spread over more than 5,200 addresses. Coinkite has halted shipments and destroyed its remaining stock carrying the vulnerable firmware.

Article image for: Coldcard theft rises to 1,816 bitcoin across 5,200 addresses

The damage from the Coldcard flaw is considerably larger than was assumed a week ago. On 5 August 2026 TRM Labs published an on-chain analysis putting the total at roughly 1,816 bitcoin, or some 116 million dollars, about €101.5 million. More than 5,200 addresses were affected. Earlier estimates ranged from 38 to 130 million dollars; the TRM figures are the first built on a complete address clustering, and they supersede last week's scattered numbers.

Where it went wrong

The cause lies in the build, not the chip. In firmware version 4.0.1 from March 2021, the configuration routed seed generation through MicroPython's software pseudo-random generator instead of the hardware RNG on the device. The design assumed 128 bits of entropy. In practice, according to the analysis, older devices sometimes retained no more than 40 bits. A key space that size can simply be walked through with modern compute.

That also explains the pattern of the theft. The first wave on 30 July drained almost 594 bitcoin from around 500 wallets in roughly 25 minutes. Three further waves followed over the next four days. Part of the final batch of transactions was still sitting in the mempool at the time of writing.

Remarkably little laundering

Steal 1,816 bitcoin and you expect to see it turn up in the mixers. That barely happened. TRM identifies a single deposit of 64.9 bitcoin at Wasabi and 200 ether to Tornado Cash on 4 August, plus one consolidation hop. There is no real layering. That may mean the attacker is not finished, or that traceability is not a concern.

What Coinkite is doing

On 3 August Coinkite said it had halted all shipments and destroyed the remaining stock carrying the vulnerable firmware. Customers are being contacted directly with an advisory and migration steps. The company says its full focus is now on helping affected users migrate safely.

What this means for you

If you own a Coldcard that was put into service in or after March 2021, assume the seed is unsafe until you have established otherwise. Generate a new seed on a device running current firmware, or use a different hardware wallet, and move your balance there. A firmware update on its own fixes nothing: a key created with too little entropy stays weak, however new the software above it. Also check that your passphrase is stored separately, because in this case it is the only remaining extra layer.

Sources: TRM Labs (on-chain analysis, 5 August 2026), Benzinga (Coinkite response, 3 August 2026). Last checked: 6 August 2026.

#coldcard#hardware wallet#security#bitcoin