The Coldcard Collapse: How a Hardware Wallet Bug Became a $120 Million Heist
2026-08-09The hack of hardware wallet Coldcard began on July 30 and is still in progress, and the numbers tell you everything about how bad this got. The exploit exposes tension between self-custody as Bitcoin's defining feature and the technical burden of securing private keys, with most losses in the first half of 2026 coming from compromised keys and operational security failures rather than smart contract hacks.
What started as a $38 million theft has ballooned into something far uglier. A security vulnerability in Coldcard is allowing hackers to drain crypto from victims' wallets, with total losses exceeding $130 million according to blockchain-monitoring firms. By early August, a third wave of sweeps tied to weak Coldcard-generated keys was targeting smaller balances while changing how funds were collected onchain.
The technical problem is straightforward enough to understand: the wallet's firmware had a flaw in how it generated private keys. Attackers didn't need to crack anything. They just needed keys that were weak to begin with. Blockaid's co-founder noted the exposure originated at the key generation stage, highlighting how users rely on security systems they never directly interact with, with a hardware wallet's security ultimately coming down to firmware and systems users interact with but never see.
This sits within a broader pattern that's becoming impossible to ignore. The dollar total isn't the most important story; the more significant shift is where attacks are coming from, with three of the four largest incidents in 2026 not involving a single line of flawed Solidity—smart contracts did exactly what they were programmed to do, given fraudulent instructions by attackers with access they shouldn't have had.
The self-custody evangelists got a hard lesson this week. For investors unwilling to accept the operational risks of managing private keys, growing availability of spot Bitcoin ETFs provides an increasingly attractive alternative. Losing $120 million to your own wallet's firmware tends to do that. Not the kind of bull case hardware makers wanted to make this cycle.
Source & further reading:
- The $120 million Coldcard wallet hack lights up Bitcoin's memory pool: Crypto Daily — CoinDesk
- Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft — CoinDesk
- Hackers steal over $130M by exploiting bug in offline hardware wallets — TechCrunch
- Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million — CoinDesk
- Coldcard exploit could boost demand for regulated bitcoin exposure, analysts say — CoinDesk
Sources
- The $120 million Coldcard wallet hack lights up Bitcoin's memory pool: Crypto Daily
- Coldcard exploit reignites Bitcoin self-custody debate after $38 million theft
- Hackers steal over $130M by exploiting bug in offline hardware wallets
- Bitcoin cold-wallet attack spreads to 4,500 addresses as losses near $89 million
- Coldcard exploit could boost demand for regulated bitcoin exposure, analysts say