Loading market data...

Coldcard Hack Drains $88.6M in Bitcoin as Galaxy Research Ties Breach to 2021 Seed Flaw

Coldcard Hack Drains $88.6M in Bitcoin as Galaxy Research Ties Breach to 2021 Seed Flaw

A Canadian entrepreneur lost 18.25 Bitcoin — worth roughly $1.6 million — from a Coldcard hardware wallet in under seven minutes on July 29, 2026. The theft is part of a much larger pattern: Galaxy Research has identified three suspected attack waves targeting Coldcard-generated addresses, draining 1,367.05 BTC (about $88.6 million) from 4,585 source addresses. The vulnerability, the firm says, traces back to a 2021 flaw in the code that generates seed phrases, with attackers allegedly using AI to brute-force affected seeds.

The July 29 attack

The Canadian victim's wallet was emptied fast — 18.25 BTC gone in less than seven minutes. That speed points to a precomputed list of vulnerable seeds rather than a real-time crack. Galaxy Research's on-chain analysis shows the stolen Bitcoin hasn't moved since; it sits in attacker-controlled addresses. The firm hasn't confirmed whether insufficient randomness in the seed generation is the root cause, but its findings rely entirely on on-chain data.

How the vulnerability works

Coldcard's default seed-generation method is described in the device's manual as 'involves the most trust' yet also 'low risk to users.' The 2021 code flaw apparently made some seeds predictable enough that AI-assisted brute-forcing became feasible. Alternatives exist — users can combine the hardware's output with dice rolls to remove trust in the hardware — but most users likely followed the default path. Galaxy hasn't publicly identified which specific Coldcard firmware versions are affected, but the attack waves suggest a broad exposure.

Who was hit

The drained holdings had sat dormant for an average of 3.18 years, meaning most victims were long-term holders — the kind of users who buy a hardware wallet and forget about it. The 4,585 source addresses span three distinct attack waves, though Galaxy hasn't said when the first wave began. The Canadian entrepreneur's case is the most recent confirmed victim, but the total haul of 1,367.05 BTC makes this one of the larger hardware-wallet breaches on record.

Coldcard has not issued a public statement about the vulnerability as of Aug. 2, 2026. Galaxy Research's analysis remains preliminary — it hasn't definitively confirmed insufficient randomness, and the firm says its conclusions are based solely on on-chain patterns. The stolen Bitcoin hasn't moved, leaving open the question of whether the attackers will try to launder it or hold. For now, users who generated seeds using Coldcard's default method after 2021 may want to consider migrating to a new wallet — or at least adding dice-roll entropy.