BTC ETH SOL BNB XRP Fear & Greed
AltcoinGordon
News

Coldcard Wallet Flaw Blamed for Bitcoin Theft, Triggers Record 233,000 BTC Move

A reported security flaw in the Coldcard hardware wallet is linked to a large Bitcoin theft and an unprecedented wave of coin migration.

Original AltcoinGordon illustration for: Coldcard Wallet Flaw Blamed for Bitcoin Theft, Triggers Record 233,000 BTC Move
Original illustration, drawn for this story by AltcoinGordon.

A reported vulnerability in the Coldcard hardware wallet has been tied to a major Bitcoin theft, according to two separate reports published on August 12, 2026. CoinTurk News put the stolen amount at roughly $130 million, while crypto.news, citing a source referred to as Gray, estimated the exposure at approximately $116 million. Both figures point to a substantial breach involving a device marketed as a secure, offline method for storing Bitcoin private keys.

Coldcard is a hardware wallet designed for self-custody, allowing users to hold their own private keys instead of relying on exchanges or third-party custodians. Devices in this category are typically viewed as among the safer options in the crypto ecosystem, since they keep keys isolated from internet-connected systems. A flaw affecting such a device raises questions about the broader assumptions underpinning self-custody security.

Alongside the theft reports, both sources noted a record migration of about 233,000 BTC. The scale of that movement suggests a large-scale reaction among holders, though the exact motivations behind each transaction were not detailed. Some of the movement may reflect precautionary transfers by users seeking to move funds to new wallets or storage methods following news of the exploit.

The discrepancy between the two theft estimates, $130 million versus $116 million, has not been resolved. Differences of this kind are common in the early stages of security incident reporting, when data sources and calculation methods can vary. Readers should treat both figures as reported estimates rather than confirmed totals until further clarification emerges.

Self-custody has long been promoted within the Bitcoin community as a defense against exchange failures, hacks, and counterparty risk. The core principle rests on the idea that users who control their own keys are not exposed to the failures of centralized platforms. An exploit affecting a widely used hardware wallet challenges that narrative, at least in the context of device-level vulnerabilities.

Hardware wallet manufacturers generally respond to reported flaws with firmware updates, security advisories, or public statements addressing the scope of any vulnerability. Neither report specified whether Coldcard’s maker had issued an official response at the time of publication. Users of the device may need to wait for further guidance before determining appropriate next steps.

The timing of the reported theft alongside the large BTC migration suggests the two events are connected, though the precise mechanics of how the exploit was used to move funds were not detailed in either report. Blockchain analysts and security researchers often examine on-chain data in the aftermath of such incidents to trace stolen funds and identify affected wallet clusters.

Sources disagree on this story

This article was published before the reports below were compared. The reporting above stands; what follows is where the published accounts do not agree.

Four outlets agree a Coldcard firmware flaw exposed Bitcoin seeds, but they report different totals for how much was stolen.

What all sources agree on

  • A firmware integration error in Coldcard hardware wallets caused affected devices to use a predictable software random-number generator instead of the intended hardware source when generating wallet seeds.
  • The flaw affected firmware versions 4.0.1 through 4.1.9, with the first vulnerable release dating to March 2021 and disclosure occurring in July 2026 (per Coinkite advisory reporting).
  • Affected seeds carried roughly 40 bits of effective entropy instead of the intended 128 bits.
  • The disclosure was followed by a large-scale, precautionary movement of Bitcoin as self-custody users moved funds to safety.

Where the reports disagree

1Total BTC stolen

Attackers drained approximately 2,100 Bitcoin across multiple attack waves.

CoinTurk News EN

Attackers have reportedly drained about 1,816 BTC worth $116 million from more than 5,200 addresses.

crypto.news

attackers drained approximately 1,816 BTC, worth about $116 million, from more than 5,200 addresses in four suspected waves that began on July 30.

The Cryptonomist EN

What would settle it: A consolidated on-chain forensic accounting from Coinkite or a blockchain intelligence firm (e.g., TRM Labs, Galaxy Research) reconciling all affected addresses.

2Total dollar value of losses

A major security breach targeting Coldcard hardware wallets has resulted in losses approaching $130 million

CoinTurk News EN

The Coldcard seed-generation failure has exposed about $116 million in Bitcoin to theft

crypto.news

Estimated exposure has been placed in the range of nine figures, with potential losses from the Coldcard hack nearing $114 million, a figure separate from the total volume of Bitcoin relocated in response.

Coincu

A flaw in Coldcard hardware wallets exposed about $116 million (1,816 BTC) across more than 5,200 addresses, according to TRM Labs.

The Cryptonomist EN

What would settle it: TRM Labs' final loss report or Coinkite's own confirmed victim/address tally, once investigators finish tracing all affected addresses.

What to make of it

Treat the underlying cause — a firmware entropy flaw affecting Coldcard versions 4.0.1–4.1.9 since March 2021 — as established, but do not cite a single dollar or BTC loss figure as final since reports range from 1,596–2,100 BTC and $114M–$130M for what may still be an evolving tally.

Market Impact

A theft of this scale, even at the lower $116 million estimate, is large enough to draw attention across the Bitcoin security community and among hardware wallet users generally. Reports of vulnerabilities in self-custody devices can prompt short-term caution among holders, sometimes visible in on-chain wallet migration patterns like the 233,000 BTC movement described here.

Beyond the immediate financial loss, incidents involving hardware wallets can affect confidence in self-custody solutions more broadly. Renewed scrutiny of wallet security practices, firmware auditing, and supply chain integrity often follows disclosures of this kind, particularly if the exploit is confirmed and its technical details become public.

The full scope of the Coldcard-linked theft, including the exact loss figure and the cause of the exploit, remains subject to further reporting and verification. The scale of the accompanying Bitcoin migration underscores how quickly holders can react to security concerns involving self-custody tools.

Frequently Asked Questions

What is Coldcard?

Coldcard is a hardware wallet designed to let Bitcoin holders store their private keys offline for self-custody, rather than relying on exchanges or third-party custodians.

How much Bitcoin was reportedly stolen?

Estimates differ between sources. CoinTurk News reported approximately $130 million in losses, while crypto.news cited a figure of about $116 million, attributed to a source referred to as Gray.

Why did 233,000 BTC move around the same time as the theft report?

Reports describe a record migration of about 233,000 BTC coinciding with the exploit disclosure, which may reflect holders moving funds as a precaution, though the exact reasons for each transaction were not specified.

Has Coldcard's manufacturer responded to the reported exploit?

Neither source referenced an official statement from the device's manufacturer at the time of publication, so any formal response remained unconfirmed.

Does this incident mean hardware wallets are unsafe?

Hardware wallets are generally considered a secure self-custody option, but any reported vulnerability, once confirmed, can prompt reassessment of specific devices or firmware versions rather than the category as a whole.