#What Happened with Coinkite and the Coldcard Breach?
Coinkite, a prominent maker of hardware wallets, is currently dealing with a significant security incident that has potentially impacted thousands of users. This incident is emerging as one of the largest hardware wallet breaches documented. A weakness in the firmware of the Coldcard wallets has led to the loss of over 1,778 Bitcoin, which is valued at around $112 million. The attacks began on July 30, 2026, and within just 41 minutes, attackers managed to steal more than 1,000 BTC from over 1,000 different wallets. As of mid-August 2026, around 1,531 BTC remains in the control of these attackers.
#How Did the Breach Occur?
The vulnerability at the heart of this breach can be traced back to a firmware update that Coinkite rolled out in March 2021, specifically version 4.0.1. This upgrade inadvertently introduced a significant flaw in the process of generating seed phrases—the crucial component that creates the master keys for controlling the wallets. Instead of utilizing a hardware random number generator to ensure unique and secure seed phrases, the flawed code redirected this essential task to a software-based pseudorandom number generator. This switch made it easier for hackers to predict outcomes, making wallets vulnerable to compromise.
Coinkite was alerted about a related issue by a developer as early as May 2025, but unfortunately, the vulnerability was not addressed in time, allowing attackers to create and utilize tools to exploit this flaw on a large scale, affecting multiple models of Coldcard wallets, including Mk2, Mk3, Mk4, Q, and Mk5. Galaxy Research confirmed that at least twelve different attackers exploited this same vulnerability.
A sharper way to see the markets in just 5 minutes.
Same news, different lens. We cut through the noise and hand you the overlooked ideas and the deeper read the crowd misses. Join 38,000+ investors seeing the markets differently.
#What Actions Has Coinkite Taken?
In response to the breach, Coinkite issued a security advisory on July 30, the day attacks began, followed by the release of patched firmware by July 31 for the affected wallet models. The CEO publicly expressed regret regarding the security breach and its implications.
For users of Coldcard wallets, it is vital to understand that merely updating the firmware is not sufficient to secure their holdings. Since the flaw was related to seed phrase generation, any seed phrases created during the compromised firmware duration will remain vulnerable, regardless of future firmware updates. Coinkite has instructed affected users to generate entirely new seed phrases using the patched firmware, and to transfer all funds to these newly created wallets promptly.
#What Does This Mean for Self-Custody?
This incident raises important concerns regarding the narrative that self-custody is inherently safer than depending on centralized exchanges. The Coldcard breach has demonstrated that when a hardware wallet is compromised at the firmware level, users become the last line of defense but are often unaware until it is too late. A flaw introduced in 2021, flagged in 2025, and exploited in 2026 presents a troubling timeline for a market that positions hardware wallets as the pinnacle of security.
Industry competitors now face pressing questions from both consumers and security professionals on how to guarantee that their random number generator implementations effectively utilize true hardware entropy, alongside the speed and effectiveness of adopting verified patches when vulnerabilities arise. This scrutiny could reshape the competitive landscape for hardware wallet manufacturers as well as user trust in self-custody solutions.