Crypto news

18.08.2026
04:55

Hackers have withdrawn over $115 million from Coldcard wallets: a massive firmware vulnerability has been exposed

The scale of the disaster surrounding Coldcard hardware wallets has turned out to be far more serious than previously assumed. According to my analysis of blockchain data, total user losses have exceeded the $115 million mark. Since July 30, attackers have withdrawn 1,778.58 BTC from 8,680 addresses. This is not just a single incident, but a systemic problem requiring immediate attention from the entire crypto community.

The root of the problem lies in the 2021 firmware

The key detail that immediately stands out: all stolen bitcoins were created after March 17, 2021 — that is exactly when the vulnerable firmware version was released (block 674,951). Not a single affected coin generated before that date has been found. This is direct proof that the vulnerability lies in key generation on devices with updated software.

The analysis showed that out of 6,303 BTC seized, none appeared before the release. The same applies to the 3,598 addresses reported by victims: the earliest one dates to March 22, 2021. This boundary leaves no doubt — the problem is embedded in the code itself, not in user actions.

Attacks: the first wave was the most destructive

The greatest damage was caused by the first wave of attacks — accounting for $70.2 million, or 61% of all losses. The speed of fund withdrawal at that time was striking: the operator emptied addresses one after another, moving funds across nine consecutive blocks in just 41 minutes. The fee was a fixed 30 satoshis per vByte, indicating a well-planned automated scheme.

Interestingly, a significant portion of the funds from the first wave remains untouched to this day: out of 108.65 BTC, 108.57 BTC are still in place. However, assets from the third wave have already been locked in "vault" scripts — 207.73 BTC, suggesting an attempt by the attackers to launder or preserve the stolen funds.

Uneven losses and underestimation of the scale

Victim reporting lags far behind reality. Only 192 people have reported losses totaling 714.81 BTC (40.2% of all stolen funds), with individual losses reaching 58.97 BTC and the median around 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC have not yet been linked to any owner. This means the real number of victims could be several times higher than what we currently see.

My verdict: this incident is a wake-up call for the entire industry. Hardware wallets were considered the gold standard of security, but now it is obvious: even they are vulnerable if the manufacturer makes mistakes in critical code. Coldcard users with firmware after March 2021 should immediately migrate to new devices and regenerate their keys. The market will no longer forgive such miscalculations — trust in hardware solutions has been undermined, and its restoration will take years.