Koinlytics

The Coldcard Loss Went From $75M to $130M in a Week and Nobody Knows the Final Number

Aug 7, 2026BTCsecurityself-custodyhardware-walletscoldcardexploits
Tracking estimates for the Coldcard hardware wallet exploit climbed from $75 million to $89 million to $116 million to over $130 million within days. At least a dozen separate attackers are draining wallets, and the affected address set is still being mapped.

The estimated loss from the Coldcard hardware wallet exploit has moved four times in under a week. Early tracking put it near $75 million. It was revised to $89 million, then to $116 million by TRM Labs, then past $130 million by August 4 according to blockchain monitoring firms cited by TechCrunch.

The number is still moving, and that is the most important fact about this incident.

Why the Figure Keeps Climbing

Two reasons, and they have different implications.

The first is that the affected address set is being mapped, not discovered all at once. The vulnerability traces to a build configuration error in a March 2021 firmware release that caused seed generation to fall back on a weak software random number generator instead of the device's hardware entropy source. Every seed generated on affected firmware between that release and the patch is potentially derivable. Analysts are working backwards from the entropy flaw to enumerate which addresses fall in the vulnerable set, and that enumeration is ongoing.

The second is that the theft is still happening. This is not a single drain event being tallied after the fact. At least a dozen different attackers are working through the address space, apparently as multiple independent groups rather than one coordinated operation, which is what you would expect once a derivable-seed flaw becomes public knowledge.

The Timeline

Five years between the flaw shipping and the flaw being exploited at scale. During that entire window, every affected device displayed as functioning normally, because it was. The seeds it generated were valid. They were just drawn from a search space small enough to enumerate.

What the Stolen Funds Are Doing

The proceeds are pooling at a small number of attacker addresses with minimal laundering so far. No layering, no mixing, no immediate movement through the usual obfuscation infrastructure.

That is unusual and it cuts two ways. It makes the funds highly traceable, which improves the odds that exchange deposits get flagged and frozen. It also suggests attackers who are not in a hurry, which is consistent with a theft that is still in progress rather than one being cashed out.

A hardware wallet's job is to generate a secret nobody can guess. This one generated secrets that could be guessed, and it did so silently for five years while displaying every sign of working correctly.

The Uncomfortable Lesson

The failure was not in the secure element, the screen, the air gap or the signing process. All of those worked. It was in a build configuration that silently substituted the wrong entropy source, in a device category whose entire value proposition is that it holds a secret you generated safely.

Three implications worth sitting with:

What to Watch

If you own a Coldcard and generated your seed between March 2021 and the patch, treat that seed as compromised and migrate to a new one. That is the concrete action, and it is worth doing regardless of whether your address has been touched, because the enumeration is not finished. If you hold funds across several hardware devices, knowing which seed came from which device and when is the kind of record that only matters on one day, and this is that day.

Powered by Koinlytics · Portfolio and DeFi analytics that see what others miss.

See every headline that moves your bag.

Koinlytics Market Intel is live inside the app. Track your portfolio, LPs and impermanent loss while the news breaks.

Join Koinlytics