Key Takeaways
- Over $130 million in Bitcoin has been stolen from Coldcard hardware wallets due to a critical firmware vulnerability affecting seed generation
- Daily Bitcoin active addresses surged to 980,000, marking the highest level since December 2024, primarily due to security-driven wallet migrations
- Security researchers have identified at least 15 distinct attackers exploiting the flaw, with evidence suggesting a fourth attack wave may be underway
- Stolen cryptocurrency totaling 64 Bitcoin and 200 Ether has been funneled through Wasabi and Tornado Cash mixing protocols
- This security breach now stands as 2026’s third-largest cryptocurrency theft incident
A critical firmware vulnerability discovered in Coldcard hardware wallets has resulted in one of 2026’s most significant Bitcoin security incidents, with total losses surpassing $130 million.
The security flaw originated in March 2021, when a firmware defect compromised the randomness mechanism used for seed phrase generation on certain devices. This vulnerability reduced cryptographic key strength from the standard 128 bits down to merely 40 bits, enabling attackers to use brute-force methods to crack wallets remotely without requiring physical device access.
Galaxy Digital’s analysis has identified no fewer than three distinct attack campaigns, successfully compromising 7,300 wallet holders. Security experts now suspect a potential fourth wave of attacks may be underway, which could drive total losses even higher.
Network Activity Surges Amid Security Concerns
According to blockchain analytics platform Glassnode, Bitcoin active addresses climbed to approximately 980,000 daily transactions in the aftermath of the security breach. This represents the network’s highest activity level observed since December 2024.
However, Glassnode emphasized that this surge should not be interpreted as bullish market sentiment. The analytics firm characterized the increase as “an operational security response, not a change in market conviction.”
Previously dormant Bitcoin holdings valued at nearly 200 times the initial theft amount have moved across the blockchain, indicating widespread precautionary measures by Bitcoin holders seeking to secure their assets.
The catalyst for this broad network response was a July 31 theft involving 594 Bitcoin, valued at approximately $38 million at that time. Subsequently, Galaxy Research verified that cumulative losses had climbed beyond 1,596 Bitcoin, representing more than $100 million in stolen funds.
Stolen Assets Transferred to Privacy Protocols
Blockchain security company CertiK has been monitoring the movement of compromised funds. Their analysis reveals that approximately 64 Bitcoin, valued at $4.17 million, was transferred to Wasabi, a Bitcoin privacy-enhancing mixing service. Additionally, 200 Ether tokens worth roughly $380,000 were routed through Tornado Cash.
CertiK analysts believe some transactions may originate from opportunistic attackers exploiting the discovered vulnerability. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK representative stated.
Analysis from TRM Labs indicates that the majority of stolen cryptocurrency remains concentrated in a limited number of attacker-controlled wallet addresses. The varying methodologies employed across different attack waves indicate involvement from at least 15 distinct threat actors.
Dragonfly managing partner Haseeb Qureshi revealed that certain artificial intelligence models successfully identified the underlying security weakness in under 20 minutes. He noted that approximately two dollars worth of AI-assisted security hardening could have potentially prevented the entire exploit.
Cybersecurity professionals warn that simply updating device firmware is insufficient protection for affected wallet owners. Users who generated wallets on potentially compromised devices are strongly urged to create entirely new wallets using secure devices and transfer their holdings immediately.
With losses exceeding $130 million, the Coldcard security breach currently holds the position as 2026’s third-largest cryptocurrency theft incident to date.


