Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
Watch Simply Bitcoin Live!
Every Monday-Friday 12:30pm Eastern
get updates
BACK TO NEWS
August 4, 2026
/
0
Min Read

Coinkite's Coldcard Wallet Bug Drains More Than $83 Million in Bitcoin as New Waves of Theft Emerge

A firmware flaw in Coinkite's Coldcard hardware wallet has turned into one of the largest self-custody losses in Bitcoin's history, with an attacker draining funds from hundreds of wallets that generated seeds on affected devices going back to March 2021.

WHAT HAPPENED

The first confirmed sweep hit in the early hours of July 30, when an attacker moved bitcoin out of roughly 500 wallets in a matter of minutes. AnchorWatch CEO Rob Hamilton tracked a total of 1,324 spent outputs in 500 transactions which took place across three blocks, with 562 BTC later consolidated into a single address. The theft did not stop there. Within days the exploit had already drained more than 1,300 bitcoin, worth roughly $83 million, from thousands of addresses across multiple waves, making it one of the biggest self-custody failures in Bitcoin history.

THE ENTROPY FLAW

The root cause traces back to how Coldcard devices generated the random seed words that protect a wallet. Coinkite says Mk3 seeds had about 40 bits of entropy instead of 128. Later models were not immune either, since only a limited portion of the intended randomness reached the seed generator on newer hardware. Coinkite CEO Rodolfo Novak, known in the community as NVK, took the blame publicly and did not soften the news.

"I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news," Novak wrote.

WHO IS AT RISK

Coinkite's own guidance draws a clear line around who needs to act. The company said customers who created their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone. Everyone else who generated a seed natively on an affected device, without added entropy or a strong passphrase, should treat their funds as exposed. Installing new firmware is not enough on its own. "Updating the firmware does not repair a seed that was generated by affected firmware," the company said.

WHAT TO DO NOW

Anyone still holding funds on an affected Coldcard should generate a fresh seed on a device confirmed to be unaffected and move funds off the old wallet rather than reuse it. Coinkite has continued patching firmware across its device lineup as investigators keep tracing new batches of stolen coins, and researchers have cautioned that any address whose public key was ever exposed on a vulnerable device remains a target until the funds are moved.

This story comes from the Simply Bitcoin Live show. Watch the full episode.

About Simply Bitcoin
Simply Bitcoin is an independent Bitcoin media network delivering daily news, analysis, and original shows. We believe in spreading the Bitcoin signal: truth, transparency, and freedom through education and self-sovereignty.

related materials

Related Stories
on Bitcoin & Freedom

all articles
Subscribe
Coinbase's John D'Agostino Tells CNBC Over 40 Countries Have Committed to Buying Bitcoin
Jul 3, 2026
They Trapped Elon Musk's Trillion. Yours Is Next. Got Bitcoin?
Jun 22, 2026
The Peaceful Revolution Nobody Sees Coming
May 26, 2026

Stay in the Loop

Get the Best Bitcoin 
Stories, Daily
Subscribe to our free newsletter for the latest Bitcoin updates, top videos, and curated market insights, delivered straight to your inbox.