Coldcard Crypto Heist: FBI Joins Hunt for $115M Bitcoin Hacker

A critical firmware bug in Coldcard Mk3 hardware wallets has led to over $115 million in Bitcoin losses. The vulnerability, which caused weak seed generation, has sparked an investigation by law enforcement and researchers. While an insider attack is speculated, evidence suggests a complex chain of errors rather than malicious intent, highlighting broader failures in open-source integration and code review.
David Isong
David IsongCrypto2 hours ago2 minute read
Coldcard Crypto Heist: FBI Joins Hunt for $115M Bitcoin Hacker

New data from Galaxy Research and other investigations have shed light on the ongoing Coldcard theft, where over $115 million in Bitcoin has been lost due to a critical firmware vulnerability. Hackers began systematically draining Bitcoin from Coinkite’s popular Coldcard hardware wallets on July 31, 2026. Galaxy Research, having engaged with over 200 victims, initially estimated losses to exceed $115 million, based on Bitcoin's price at the time of the attack, with later estimates suggesting total losses could surpass $130 million or even 1,800 BTC across multiple waves from more than 5,000 addresses.

The root cause of this massive theft was identified as a firmware bug in Coldcard Mk3 devices, specifically starting with version 4.0.1 in March 2021. This flaw caused seed generation to incorrectly fall back to a weak software Pseudorandom Number Generator (PRNG), MicroPython’s Yasmarang, instead of utilizing the hardware true random number generator. This critical error drastically reduced the entropy of the generated Bitcoin private keys to roughly 40-72 bits, making them effectively guessable by modern computing hardware. Coinkite acknowledged that the bug “silently went unnoticed” and its “potential impact grew with every release” of its products, urging users to immediately move their funds.

Law enforcement may already possess concrete leads on the identity of the attacker responsible for the first and largest wave of the July 2026 drains. Block's investigation, led by Clay Garrett, traced the attacker’s on-chain sweeps to a paid account at a major blockchain data provider. The provider's internal logs matched the theft pattern with “extraordinary specificity,” including the number, timing, and sequence of requests. Alex Thorn of Galaxy Research publicly stated that

Loading...