Industry News

Coldcard Hardware Wallet Hack: Attacker Moves $7.7M as Laundering Continues

Crypto Economy · 7 Sept 2026
Key Takeaway If your business holds cryptocurrency in a Coldcard or similar hardware wallet, check for firmware updates immediately and move funds to a newly generated seed rather than assuming an update alone fixes the risk.

Researchers at Galaxy Research are tracking a new wave of activity from the attacker behind the Coldcard hardware wallet theft. The exploiter has moved 97.09 BTC (worth about $7.7 million) using THORChain and CoinJoin transactions, both of which are designed to obscure the trail of stolen funds by mixing them with other users' transactions.

The theft stems from a firmware flaw discovered on July 30 that weakened the randomness Coldcard devices use to generate wallet seeds, the secret codes that secure a cryptocurrency wallet. This allowed the attacker to create 293 separate vaults holding victims' coins. Coinkite, the maker of Coldcard, has since released fixed firmware, but the update cannot repair wallets that were already compromised. Affected users must generate entirely new seeds and move their funds to new, secure wallets.

Galaxy Research estimates the wider Coldcard incident may total around 1,806 BTC, or roughly $143.9 million, making it one of the largest crypto security incidents of the year. About 82% of the stolen funds remain sitting in attacker-controlled addresses, while 18% has now been moved in an apparent effort to launder it.

This story mainly concerns hardware wallet users rather than typical small businesses, but it is a useful reminder for any business holding cryptocurrency assets.

Summarised by CISO AI from Crypto Economy. We link back to every original so you can read it yourself.