
Blockchain analytics account Lookonchain, citing Galaxy Research, reported that losses associated with the Coldcard security incident may have reached 2,055 Bitcoin, valued at approximately $130 million.
This is insane!
— Lookonchain (@lookonchain) August 4, 2026
According to @glxyresearch, the total losses from the #Coldcard hack may have reached 2,055 $BTC($130M).
More than 7,700 victim addresses have been affected. pic.twitter.com/GizWlDbYpz
Lookonchain stated that more than 7,700 addresses may have been affected, compared with an earlier estimate of more than 4,500 addresses and 1,367 Bitcoin in losses.
The figures remain preliminary and could change as analysts continue tracing transactions.
The address total is not equivalent to a victim count, as one person may control multiple Bitcoin addresses.
Lookonchain did not provide a detailed methodology for calculating its latest estimate.
How an Offline Wallet Could Be Affected
Coldcard devices, manufactured by Canadian company Coinkite, are designed to keep private keys isolated from internet-connected systems.
The reported attack did not depend on connecting remotely to the physical wallets. Instead, it exploited reduced randomness in seeds created by certain firmware versions, according to technical assessments.
A recovery seed, usually recorded as a series of words, is used to derive the private keys controlling a wallet.
Sufficient randomness makes it computationally impractical for another party to reproduce the seed.
Reports from Block and Coinkite concluded that a firmware integration error caused some Coldcard devices to use a software-based random-number generator instead of the intended hardware source.
“The cryptographic choice was sound. The integration was not,” Coinkite said.
Block and Coinkite have offered different estimates of how much effective randomness remained in some device models.
Both assessments, however, concluded that the seed-generation process did not use the intended hardware randomness as designed.
The reduced search space could allow an attacker to test possible seeds offline. A device could therefore remain disconnected from the internet while controlling funds associated with a vulnerable seed.
Coinkite identified firmware versions 4.0.1 through 4.1.9 on Mk2 and Mk3 devices as the most severely affected.
The company reported that seeds generated on Mk4, Mk5, and Q devices before recently released fixes were also affected, although it assessed the impact on those models as less severe.
Available loss estimates do not establish which device model was associated with each affected address.
To illustrate the difference in keyspace, the Bitcoin Policy Institute compared finding a properly generated Bitcoin key to locating one atom across 2 billion galaxies.
By contrast, it likened the pool associated with affected Coldcard firmware to the atoms in a large virus, a range it reported that a standard computer could search within hours.
We made a short visual explainer to help people understand the Coldcard bug, and what it means for the security of affected wallets.
— Bitcoin Policy Institute (@bitcoinpolicy) August 3, 2026
Bitcoin's entire security model depends on a user's ability to select astronomically large numbers from a truly random set.
If you imagine every… pic.twitter.com/WFryUWnJnL
Coldcard User Reports Seven-Minute Theft
Canadian entrepreneur Jonathan Goodman reported that three of his wallets were emptied between 9:36 p.m. and 9:43 p.m. on July 29th.
He placed his loss at 18.25245043 Bitcoin, valued at approximately C$1.6 million at the time.
In an X post, Goodman wrote that his Coldcard had never been connected to the internet and was stored in a bank safety deposit box.
$1.6 million dollars in Bitcoin was drained from my account on July 29th in the Cold Card wallet hack.
— Jonathan Goodman 🇨🇦 (@itscoachgoodman) August 1, 2026
My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet.
This part's nerdy, but here's… pic.twitter.com/Lf9kJv9Jo4
He added that he had not disclosed his seed phrase and initially believed the vulnerability did not affect him.
“Perhaps the hardest part about this is that I did everything right,” Goodman wrote.
He also outlined plans to file reports with police and the Ontario Securities Commission, although he did not expect to recover the Bitcoin.
Coinkite Issues Migration Guidance
Coinkite has released corrected firmware for each affected model and release track, with the relevant versions listed in its security advisory.
The update fixes the original seed-generation vulnerability for newly created wallets, but it does not repair seeds generated by affected firmware.
Users whose seeds were created without at least 50 independent and private dice rolls are advised to generate a replacement, verify the backup and receiving address, and complete a test transaction before transferring the remaining funds.
Coinkite recommends migration even when a strong BIP-39 passphrase is in use.
However, the July 31st hotfix may have introduced a separate problem unrelated to the original theft mechanism.
The X account +rapidlab309 cited an open code review indicating that a temporary hardware random-number-generator error could prevent a device from reaching the PIN screen, effectively leaving it unusable.
Confirmed #COLDCARD bricked 💀
— +rapidlab309 (@rapidlab309) August 3, 2026
A rushed firmware hotfix introduced a critical failure: a transient STM32 TRNG error could permanently fault the RNG. Since it’s used before the PIN screen, affected devices to become effectively bricked.https://t.co/qloYvCygAm
The review’s author had not independently confirmed the reported failures on physical devices. A repository collaborator subsequently submitted a proposed fix, which remained under review.
People who believe their funds were stolen may need to preserve their devices, seed backups, and transaction records.
JAN3 CEO Samson Mow also recommended documenting relevant details, contacting law enforcement, and avoiding anyone requesting a seed phrase or payment for recovery services.
Custody Practices Draw Renewed Attention
Mow characterized the incident as particularly significant for people who had moved their Bitcoin away from exchanges and into self-custody.
The COLDCARD RNG vulnerability may be worse than an exchange hack. It hit at the core of sovereign Bitcoin holders - it struck those who did all the research, understood why self-custody is important, and didn’t keep coins on exchanges.
— Samson Mow (@Excellion) August 1, 2026
My heart goes out to everyone affected.…
“Self-custody only works if you do it in a way that minimizes a single point of failure. Don’t trust any single vendor for hardware,” he wrote.
He advocated multisignature arrangements using hardware from different manufacturers for substantial holdings.
These arrangements may reduce reliance on a single device or vendor, although they introduce additional setup, backup, and recovery requirements.
Mow also acknowledged that custodial accounts, exchange-traded funds, and other alternatives involve different risks, including dependence on third parties.
The incident has renewed attention to the distinction between storing a private key offline and generating it securely.
Offline storage can limit several forms of remote access, but its effectiveness also depends on the seed-generation process and the wallet’s broader configuration.
