Key Points
- Attackers exploited a firmware vulnerability from March 2021 to steal more than 1,778 Bitcoin from Coldcard hardware wallet users
- Total verified losses exceed $112.7 million, affecting over 8,600 wallet addresses
- Galaxy Research assesses that hackers leveraged unrestricted AI systems to identify and weaponize the security flaw
- Security experts claim AI safety regulations at US laboratories prevented defenders from accessing comparable tools for protection
- Multisignature wallet configurations remained secure; all affected users must create fresh seed phrases on updated firmware
A security vulnerability concealed within Coldcard firmware dating back to March 2021 enabled malicious actors to extract more than 1,778 Bitcoin from approximately 8,600 wallet addresses, representing the most significant hardware wallet security incident to date. Based on current market valuations, verified financial damages amount to $112.7 million.
The coordinated assault commenced on July 30, 2026. In a rapid 41-minute window, attackers successfully transferred over 1,000 Bitcoin from more than 1,000 separate addresses. Blockchain analysis shows no additional malicious activity since August 6.
The vulnerability originated from a firmware modification deployed by Coinkite in release 4.0.1. This update inadvertently redirected the seed phrase creation mechanism from a hardware-based random number generator to a software-driven pseudorandom number generator. Software-generated randomness exhibits greater predictability patterns, significantly weakening the cryptographic security of generated private keys.
According to reports, a developer alerted Coinkite to a connected issue as far back as May 2025. The security gap remained unaddressed for an extended period, providing attackers sufficient time to develop and execute exploitation frameworks targeting multiple Coldcard device generations, including Mk2, Mk3, Mk4, Q, and Mk5 models.
Artificial Intelligence Utilized by Attackers and Defenders
Galaxy Research concluded with substantial certainty that attackers employed AI systems lacking cybersecurity safeguards to identify and weaponize the vulnerability. The open-source Kimi K3 model, recently made available to the public, represents the category of technology likely deployed in the attacks.
Rob Hamilton, who leads Anchorwatch as chief executive, explained that security protocols implemented at leading US AI research facilities effectively prevented white-hat researchers from utilizing comparable AI systems for defensive purposes. This limitation forced cybersecurity professionals to depend on the identical Chinese open-source AI models employed by the attackers.
Hamilton joined forces with approximately 25 other security specialists, including developer James O’Beirne and Calle from the Cashu project, to establish what they’ve designated the Bitcoin Red Team. This collaborative group has undertaken systematic code repository analysis throughout the cryptocurrency ecosystem to identify security weaknesses and provide remediation recommendations.
Coinkite published a security bulletin on July 30 and distributed corrected firmware by July 31. CEO Rodolfo Novak released a public statement of apology.
Essential Actions for Affected Users
Installing updated firmware alone provides insufficient protection. Any seed phrase created using compromised firmware versions remains permanently vulnerable. Users must generate an entirely new seed phrase using patched firmware versions and transfer all assets to newly created wallet addresses.
Among the 1,778 Bitcoin verified as stolen, 1,531 Bitcoin currently sits untouched in addresses controlled by the attackers. Approximately 246 Bitcoin has been transferred, with 65% entering Coinjoin privacy mixing services and 35% moving through blockchain pathways engineered to hide transaction origins.
Significantly, zero thefts occurred from multisignature wallet configurations. Multisig arrangements demand multiple independent keys for transaction approval, rendering a single compromised seed phrase insufficient for unauthorized fund transfers.
Galaxy reports distributing attacker-controlled wallet addresses to cryptocurrency exchanges, compliance organizations, and law enforcement agencies with the objective of freezing assets should they appear on centralized trading platforms.
This incident represents the twentieth-largest cryptocurrency theft in recorded history, positioned beneath Multichain’s $130 million breach in July 2023 and exceeding the $100 million stolen from Harmony’s Horizon bridge during June 2022.


