Bitcoin's 'safest' wallet just got brute-forced — the $116M Coldcard hack, decoded

The most-trusted way to store Bitcoin just got brute-forced. Since roughly July 30, attackers have drained about $116 million in BTC — around 1,367 coins from 4,585 wallet addresses — out of Coinkite's Coldcard, the hardware wallet long sold as one of Bitcoin's safest cold-storage options. TRM Labs is calling it the largest hardware-wallet exploit of the year, and independent trackers say the tally is still creeping higher.
What actually broke
This wasn't phishing or a stolen device. A build error in a March 2021 firmware release quietly made some Coldcards generate their seed from a weak software random-number generator instead of the chip's hardware entropy source. That collapsed effective key strength from the designed 128 bits to as little as ~40 bits on older devices — low enough to brute-force offline. The attacker rebuilds candidate seeds on their own machines, derives the addresses, checks them against the public blockchain, and sweeps whatever matches — never touching the device. In the first wave, ~594 BTC (~$38M) left about 500 wallets in roughly 25 minutes.
The market read-through
Coinkite is private, so there's no stock to short here — but the second-order effect is real. The whole pitch of self-custody is "not your keys, not your coins." When the gold-standard cold wallet gets emptied, some holders don't get braver — they hand their coins to someone else's vault. CoinDesk reports the exploit is already pushing nervous investors toward spot Bitcoin ETFs. That's a concrete tailwind for custodial exposure: BlackRock's IBIT and rival spot-BTC ETFs, plus custody-heavy names like Coinbase (COIN), stand to capture flows that would otherwise have gone into a ~$150 metal box. Bitcoin's price barely flinched (~$65K, up ~3% on the week) — this is a trust story, not a price crash.
What to watch
The one number that flips the mood is the stolen total. It's climbed in waves — roughly $38M → $70M → $89M → $116M+ — so watch whether it keeps rising, and whether Coinkite ships a verified fix and exchanges blacklist the consolidation address the coins are pooling into. If you generated a seed on an affected Coldcard between the 2021 firmware and the patch, treat it as compromised and migrate to a new device now.
As of 14:31 IST / 05:01 ET, Sun 9 Aug 2026. Sources: TRM Labs, Bloomberg, CoinDesk. For discussion and education only — not investment advice. Verify before acting.
This article is for educational and informational purposes only. It is not financial advice, investment recommendation, or a solicitation to buy or sell securities. Investing involves significant risks. I am not a SEBI-registered investment advisor. Readers should consult their own financial advisor and conduct their own research before making any investment decisions.
Comments
Join the conversation
Sign in to join the conversation.
Follow replies, add your view, and take part in the discussion.
Sign in to commentLoading comments...