Industry News

Coldcard Wallet Hacker Moves $7.7M in Stolen Bitcoin, Using Mixers to Cover Tracks

Decrypt · 7 Sept 2026
Key Takeaway If your business uses Coldcard hardware wallets, check whether your seed was generated on the affected firmware and, if so, create a new wallet and move your funds immediately.

An attacker who stole Bitcoin from Coldcard hardware wallets has moved 97.09 BTC, worth about $7.7 million, roughly 45% of the total taken in the latest theft wave. Researchers at Galaxy Research say the funds moved through THORChain into Ethereum and, more recently, into CoinJoin rounds, a Bitcoin privacy technique that mixes transactions from multiple users to make coins harder to trace.

The thefts stem from a firmware bug that Coinkite, the maker of Coldcard wallets, introduced in March 2021. The flaw rerouted seed generation away from the device's hardware random-number chip to a weaker software substitute, cutting key strength dramatically and allowing attackers to reconstruct private keys offline. The attacker built 293 multisig vaults to organise the stolen funds and has been draining them in order of size, with 11 now empty.

Coinkite has since released updated firmware requiring users to supply their own randomness, but this cannot fix wallets that were already generated under the flawed version. Anyone whose Coldcard was set up on affected firmware needs to create a new seed and transfer their funds. Coinkite's CEO has publicly apologised and a full technical review is still being prepared.

Summarised by CISO AI from Decrypt. We link back to every original so you can read it yourself.