Coldcard maker Coinkite is preparing a detailed technical post-mortem following a firmware exploit that drained more than $100 million in Bitcoin. The company told Bloomberg it will not speculate on customer losses until its investigation is complete, prioritizing verified facts over early estimates.
The hack has been traced to a random number generation flaw introduced during a 2021 code migration. Affected Coldcard firmware used a predictable software-based random number generator instead of the intended hardware source, weakening wallet seed generation. Researchers found the flaw reduced the possible seed search space to roughly 40 bits on Mk2 and Mk3 devices and around 72 bits on later models. Even updating the firmware does not repair seeds already compromised—users must generate new seeds with patched firmware and transfer their Bitcoin to a safe wallet.
Galaxy Research has verified 1,596 BTC stolen from approximately 7,300 addresses in three coordinated attack waves. A broader analysis suggests four waves involving about 5,294 addresses and 1,815.75 BTC, but these figures remain estimates based on blockchain transaction patterns. On August 7, 2026, blockchain tracker Lookonchain reported that a wallet linked to the exploit moved 30 BTC (worth $1.94 million) to a new address, indicating the attacker is still active.
Coinkite noted its privacy-focused design prevents it from independently confirming the total amount stolen—commonly cited as $130 million—and stressed that the incident affected wallet seed generation, not Bitcoin's underlying network or cryptography. The company will continue publishing real-time updates via its blog before releasing a comprehensive final report, which is expected to shape security best practices across the hardware wallet industry.