Security

Coldcard's Five-Year Firmware Flaw Drained $116 Million: What the On-Chain Forensics Reveal

2026-08-21

Beginning July 30, 2026, an attacker exploited a five-year-old firmware flaw in Coinkite's Coldcard hardware wallet to systematically drain bitcoin from affected devices. This is the third-largest crypto hack of 2026, bringing the year's total past $1.2 billion across 276 incidents.

What makes this one stand out isn't just the dollar figure. It's what happened after the theft—or rather, what didn't happen. According to TRM, most victim funds are pooling at a small number of attacker-controlled addresses. The laundering of these funds so far has been limited to a single 64.9 BTC Wasabi deposit and 200 ETH deposited to Tornado Cash on August 4, 2026.

That's the forensic fingerprint of someone who doesn't know what they're doing. Where remaining funds have moved past the initial receiving address, it has amounted to a single additional hop of consolidation rather than any attempt at layering or mixing. This points to an attacker, or attackers, potentially still working out how to move a sum large enough to attract attention wherever it lands. Compare that to professionals. Some professional crypto hackers, like North Korea's TraderTraitor, often begin aggressively laundering stolen funds within hours or days.

The attackers even got dunked on in the blockchain itself. Analysis of the OP_RETURN fields identified numerous spam messages directed at the hackers. One such message offered to launder the stolen funds in exchange for a 7% fee. Someone put a business card in their wallet.

Anyone who generated a seed on a Coldcard between March 2021 and the patch should treat it as compromised and migrate to a new seed. That's a five-year window. The flaw itself has been patched, but the damage to self-custody confidence is already done. For years, hardware wallets have sold themselves as the ultimate self-sovereignty play: cold storage, no intermediaries, your keys, your coins. A flaw in popular hardware wallet maker Coinkite's Coldcard allowed attackers to recreate wallet recovery phrases and steal bitcoin from what users believed were securely self-custodied wallets.

The irony is almost perfect. The one thing that hardware wallets promised you didn't have to trust anyone. And it took a five-year engineering oversight to break that promise for anyone holding a Coldcard between 2021 and now. Transaction patterns suggest multiple attackers may be involved, so TRM isn't attributing the theft to a specific actor yet. What we do know is that whoever took the bitcoin doesn't seem to know what to do with it—and that's the only piece of good news here.


Source & further reading:

Sources