Industry News

Coldcard Wallet Hack: Attacker Begins Laundering $7.8 Million in Stolen Bitcoin

Crypto Briefing · 7 Sept 2026
Key Takeaway Businesses using hardware wallets or similar cryptographic devices should confirm firmware history and regenerate any keys or seeds created during known vulnerability windows, rather than assuming a software update alone resolves the risk.

The perpetrator behind the third wave of attacks on Coldcard hardware wallets has begun cashing out stolen funds, moving roughly 97 BTC (about $7.8 million) through cross-chain swaps and Bitcoin mixing services over a five-day period. Galaxy Research identified the activity, noting the funds were first swapped into Ether via THORChain before being run through CoinJoin transactions, a technique that obscures transaction trails by bundling multiple users' funds together. The attacker appears to be targeting the largest wallets first, suggesting a deliberate, planned laundering strategy rather than a rushed cash-out.

The root cause traces back to a March 2021 firmware update from Coinkite that introduced a bug causing Coldcard devices to default to a weaker, software-based method of generating random numbers instead of using the device's hardware generator. This meant wallet seeds created during the vulnerable period had far less randomness than modern security standards require, making it possible for skilled attackers to reconstruct private keys through offline computation. Coinkite has since patched the firmware, but any wallet seed generated during the flawed window remains at risk even if the device software has been updated; affected users must generate new seeds and move their funds.

Galaxy Research has tracked this exploit chain since attacks began in mid-2026, with confirmed losses now around 1,789 BTC (approximately $114.7 million) across more than 8,865 affected addresses, and further analysis suggesting total losses could rise slightly higher.

Summarised by CISO AI from Crypto Briefing. We link back to every original so you can read it yourself.