Key Takeaways
What Happened
In late July 2026, a long-standing flaw in Coldcard, one of the most popular Bitcoin hardware wallets, was exploited to drain millions in minutes.
The problem is a seed-generation flaw. When you set up a hardware wallet, it creates a random secret—the seed—that controls your funds. Security depends on that seed being truly unpredictable. On affected Coldcard devices, a firmware bug reportedly caused the device to bypass its hardware randomness source and fall back to a predictable, software-based value seeded from non-secret chip data. The result was seeds with roughly 72 bits of entropy instead of the intended 128, which was weak enough that an attacker could reproduce them. [1] [3]
On July 31, 2026 (UTC), an attacker reportedly used that weakness to sweep about 594 BTC, worth roughly $38 million, from around 500 wallets in a window of about 25 minutes. Every drained wallet was single-signature, and each held more than 0.15 BTC. The flaw had been present in firmware since March 2021, so exposed wallets were created across a multi-year span. [1] [2]
Who Should Be Worried
You have reason to check if all of the following are true: your seed was generated on the Coldcard device itself, not rolled with dice or imported, and it was created while the device ran affected firmware. As reported from Coinkite’s notice, that means Mk3 devices on firmware 4.0.1 or later, Mk4 and Mk5 devices before version 5.6.0, and Q devices before version 1.5.0Q. Single-signature wallets are the most exposed. [2] [4]
If you use a Coldcard, this situation needs immediate attention. However, it's important not to panic. The safest short-term solution is to move your bitcoin to a brand new wallet created with a new seed or back to an exchange while you evaluate your next steps. Always send a small test transaction first and verify the receiving address before moving the rest of your funds.
If you want to learn more about this situation, the best place to start is by reading Block's research, which explains how the vulnerability worked and which devices are affected.
If your setup is particularly complex, such as multisig, multiple wallets, or a significant bitcoin balance, consider working with a professional before making changes. Companies such as Unchained provide collaborative custody and bitcoin security assistance. Never share your seed phrase, PIN, password, or authentication codes with anyone claiming to help.
Additionally, the BlockOps team found this Cyber Scrilla video walkthrough to be a helpful explanation of the vulnerability and recovery process.