Hackers exploited a software flaw in Coldcard Bitcoin wallets that allowed them to predict seed phrases and steal funds, causing losses of about 1,367 Bitcoin valued at $86 million as of August 3, 2026 [1, 2, 3, 4]. Coldcard devices create seed phrases, long strings of words used to access wallets, through a random-number generator; the flaw involved this generator relying on deterministic values such as device serial numbers, weakening security and exposing users to attacks [1, 2, 3, 4].

On July 29, Jonathan Goodman, a Coldcard user, had his three wallets drained between 9:36 and 9:43 pm. "The moment it loaded I knew I was screwed because I saw red lines for withdrawals," he said. "Between 9.36 and 9.43pm on July 29th, all three of my wallets were completely drained" [1].

Early loss estimates on July 31 placed damage at around $38 million, but the figure rose over the following days as more wallets were compromised, reaching over 4,500 in total by August 3 [1, 2, 3, 4]. Cold wallets like Coldcard are usually considered among the safest places to store cryptocurrency because they are offline from the internet, but this incident exposed risks tied to flawed device design [1, 2, 3, 4].

Aneirin Flynn, CEO of Failsafe, said, "It exposes the fallacy of your crypto being offline. The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered" [1].

Coinkite, the maker of Coldcard, notified users about the vulnerability in late July and early August 2026 and released fixed firmware for all affected Coldcard models and release tracks to address the issue [1, 2, 3, 4].