Coldcard Exploit Drains Over $130 Million in Bitcoin as Hackers Move Funds to Mixers
TLDR
- A firmware flaw in Coldcard hardware wallets has led to losses of over $130 million in Bitcoin across multiple attack waves
- Bitcoin active addresses hit 980,000 per day, the highest since December 2024, driven by security concerns not market optimism
- At least 15 different attackers exploited the vulnerability, with a fourth wave suspected
- Hackers sent 64 Bitcoin and 200 Ether to crypto mixing services Wasabi and Tornado Cash to obscure stolen funds
- The Coldcard exploit is now the third-largest crypto hack of 2026
A firmware flaw in Coldcard hardware wallets has triggered one of the biggest Bitcoin security events of 2026, with losses now estimated at over $130 million.
The #Coldcard hacker, who stole 2,055 $BTC($130M), is active again.
An hour ago, the hacker transferred 30.185 $BTC($1.94M) to a new wallet.https://t.co/Edirjbd2G0https://t.co/ksoTpGxx3g pic.twitter.com/VTL5UB9xgH
- Lookonchain (@lookonchain) August 7, 2026
The vulnerability dates back to March 2021, when a firmware bug weakened the randomness of seed generation on affected devices. This cut key strength from 128 bits to just 40 bits, making wallets brute-forceable without any physical access.
โฆ Continue reading the full article at the original source below.


