Coldcard Losses Hit $111M; 4,962 Bugs Found
Confirmed losses from the Coldcard firmware exploit have reached $111 million, with Galaxy Research warning the true figure likely exceeds $130 million as its investigation continues. Analysis of 250 victim reports shows a median individual loss of 1.022 BTC and an average of 4.04 BTC, with one holder losing 58.97 coins. Bitcoin is trading at $64,845, up 0.95% over 24 hours, as the breach continues to dominate security discussions across the ecosystem.
The theft stems from a firmware flaw introduced in Coldcard Mk3 version 4.0.1, shipped in March 2021. That update replaced the device’s STM32 hardware true random number generator with MicroPython’s Yasmarang pseudorandom number generator, reducing seed entropy to roughly 40 bits on Mk3 devices and 70 bits on later Mk4, Mk5, and Q models. Both fall well short of the 128 bits required for a secure 12-word seed phrase, leaving private keys vulnerable to brute-force reconstruction. Coinkite has disputed characterizations of the flaw as a deliberate fallback, arguing that Yasmarang was an upstream MicroPython generator rather than an intentional design choice by the company.
Attacker Moves $1.94M as Red Team Flags 85 Critical Bugs
On August 7, on-chain tracker Lookonchain flagged the first movement of stolen funds since the initial theft: 30.185 BTC, worth approximately $1.94 million, transferred to a newly created address. That transfer represents roughly 1.5% of the estimated 2,055 BTC linked to the attack. Galaxy Research noted that approximately 90% of stolen funds had remained stationary before this movement, and has shared attacker and victim address data with U.S. law enforcement and cryptocurrency exchanges. Whether further transfers follow remains unconfirmed.
Separately, a volunteer group called the Bitcoin Red Team, led by AnchorWatch CEO Rob Hamilton, completed an AI-assisted audit of 390 open-source Bitcoin repositories in 27 hours, surfacing 4,962 vulnerabilities across the ecosystem, 85 of them classified as critical. The audit scope extended well beyond Coldcard, treating the hack as a catalyst to examine how broadly the industry has underpriced randomness-related risk in open-source tooling. With 516,176 active addresses on-chain at time of writing and a hash rate of 803.2 EH/s, the underlying network remains robust, but the Red Team’s findings confirm that protocol strength does not automatically extend to the software layer above it.
Data Policy Reversal and the Self-Custody Reckoning
Coinkite has also reversed its longstanding practice of automatically deleting customer records, citing anticipated legal obligations tied to the July 30 disclosure. Previously, the company retained only email addresses and countries of residence before purging data after 120 days. The company did not specify which additional data it will now retain or for how long, and the reversal sits in direct tension with the privacy-first principles that drew many users to hardware wallets in the first place. As our earlier coverage of the four confirmed attack waves and 15 identified attackers documented, the incident has already been classified by TRM Labs as the third-largest crypto hack of 2026, a year in which the industry has lost more than $1.2 billion across 276 incidents.
The constructive takeaway is real, even at this cost: users who added sufficient dice-roll entropy during seed generation were largely protected, and the Red Team’s rapid audit demonstrates that the developer community can mobilize fast when the stakes become undeniable. The infrastructure is worth defending. Defending it well requires treating security audits as ongoing obligations, not post-incident reactions.