Skip to main content Scroll Top

Coldcard Bitcoin Wallet Loss Investigation

Coldcard Bitcoin Wallet Loss Investigation

Peiffer Wolf is investigating potential claims on behalf of Bitcoin owners who lost access to their coins or funds after a firmware flaw in Coldcard hardware wallets allowed hackers to regenerate victims’ seed phrases and drain their wallets. These wallets were manufactured by Coinkite.

If you stored Bitcoin on a Coldcard device and your funds were swept, stolen, moved, or taken without your authorization, contact Peiffer Wolf at 585-310-5140 or fill out an online contact form for a FREE Consultation.

“All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.”

— A Coldcard owner describing the flaw, as reported by TechCrunch, August 4, 2026

Coldcard Loss Investigation | Did You Store Bitcoin on a Coldcard Wallet?

On August 2, 2026, Coindesk reported that security researchers had documented a recent wave of thefts targeting Bitcoin held in Coldcard hardware wallets. The root cause was not a phishing scam, a leaked password, or a device that “touched the internet.” It was a defect in the wallet’s own firmware. The agreement further alleges starting March 2021 Coldcard build-routed seed generation to a predictable software randomizer instead of the chip’s hardware random-number generator, producing seed phrases that could be reproduced — and the corresponding private keys guessed — entirely offline and at scale.

The result: owners who did everything a hardware-wallet manufacturer tells them to do — keep the seed private, keep the device offline, never share the recovery words — have still watched their Bitcoin disappear.

If you purchased or used a Coldcard wallet and have suffered a loss, you may have a claim against the parties responsible for designing, testing, and distributing the defective firmware. It is imperative to seek legal advice promptly, as legal deadlines may apply.

You may qualify for this investigation if:

  • You generated a Bitcoin seed phrase on a Coldcard (Mk2, Mk3, Mk4, Mk5, or Q) device.
  • Your Coldcard was running vulnerable firmware from March 2021 onward.
  • Bitcoin was swept, transferred, or drained from your wallet without your authorization.
  • You did not use a strong, unique passphrase or a long independent dice-roll seed.

Coldcard Bitcoin Theft | Timeline

March 2021 — A Coldcard firmware build introduces the defect: seed generation is routed to a predictable software randomizer rather than the device’s hardware entropy source. The flaw ships — undetected — for roughly five years.

July 30, 2026 — Wave 1 — Attackers drain approximately 1,083 BTC from 1,196 addresses in just 41 minutes. Coinkite publishes a security advisory the same day.

August 1, 2026 — Coinkite updates its advisory, confirming that seeds on Mk4, Q, and Mk5 devices before the fixed firmware carried roughly 72 bits of entropy instead of the expected 128 bits.

August 2, 2026 — Galaxy Research reports the attack has spread to 4,585 addresses, with losses of about 1,367 BTC (nearly $89 million) across three waves.

August 4, 2026 — Estimated losses climb toward $130 million. Galaxy Research identifies at least a dozen separate attackers and projects total exposure of up to 2,055 BTC if a fourth wave is confirmed. Elliptic co-founder Tom Robinson corroborates the $130 million figure.

Coldcard Wallet Attack | How the Flaw Worked and Who May Be Liable

A hardware wallet has one job: generate and protect the secret keys that control your Bitcoin. The security of those keys depends entirely on randomness. A seed phrase generated with genuine 128-bit entropy is, for all practical purposes, impossible to guess. But researchers at Block determined that affected Coldcard firmware generated seeds that were predictable — built from a software pseudo-random source rather than the hardware chip’s true randomness. That collapsed the search space from astronomically large to something attackers could brute-force. In the words of researchers, the exploit let hackers “cut keys at scale” rather than break into individual safes, one at a time.

Owners who purchased a Coldcard did not agree to this risk. They allegedly paid a premium for a device marketed on the promise of superior, offline, hardware-grade security. When a product fails to perform as represented and causes financial harm, the law may provide remedies.

Peiffer Wolf is investigating potential claims against Coinkite (the manufacturer of Coldcard) and any other parties involved in the development, testing, marketing, or distribution of the affected firmware, under theories that may include product defect, negligence, breach of warranty, and misrepresentation. Owners who lost funds may be entitled to pursue recovery, regardless of where they purchased the device.

Coldcard Loss Investigation | Real People, Real Losses

These are not paper losses. Jonathan Goodman, one Coldcard owner, reported losing approximately $1.6 million in Bitcoin. He emphasized that he “never shared” his seed phrase and that his “devices never touched the internet” — precisely the precautions a hardware-wallet owner is told will keep funds safe. The theft happened anyway, because the vulnerability lived inside the device from the moment the seed was created.

Across the confirmed waves of attacks, thousands of addresses were alleged to have been affected, with the average Coldcard victim in later waves losing roughly a tenth of a Bitcoin per swept address — and many losing far more. If you are a Coldcard owner who has suffered a loss, you are not alone, and you should not assume that nothing can be done. Contact Peiffer Wolf at 585-310-5140 or fill out an online contact form for a FREE Consultation.

The Numbers | Nearly $130 Million in Bitcoin Drained

table1

Figures are drawn from public reporting by CoinDesk, TechCrunch, The Block, Galaxy Research, Block, and Coinkite, and continue to evolve as the investigation develops.

Affected Coldcard Models and Firmware

According to Coinkite’s own security advisory, the following devices and firmware versions are implicated:

table2

If you still hold Bitcoin on an affected Coldcard, act now. Coinkite allegedly advises owners to update to fixed firmware, generate a brand-new seed on the updated device, verify the backup, confirm a fresh receive address on-screen, and move funds with a small test transaction first. A strong, unique BIP-39 passphrase — or a seed built from 50 to 98 independent private dice rolls — may protect against this specific flaw. Protecting remaining funds does not waive your right to pursue a claim for losses already suffered.

FREE Consultation — We Fight for You

Peiffer Wolf represents investors and asset owners against the firms and manufacturers whose failures cause financial harm. Our attorneys are investigating the Coldcard seed-generation flaw and the resulting Bitcoin losses on behalf of affected owners nationwide. There is no cost to speak with us, and we handle qualifying cases on a contingency basis — you owe nothing unless we recover for you.

If you purchased or used a Coldcard hardware wallet and lost Bitcoin, contact Peiffer Wolf at 585-310-5140 or fill out an online contact form for a FREE Consultation. As legal deadlines may apply, you should consider seeking legal advice promptly.

FAQ

What is the Coldcard Bitcoin wallet vulnerability?

Security researchers determined that certain Coldcard hardware wallets, made by Coinkite, generated seed phrases using a predictable software randomizer instead of the device’s hardware random-number generator. Beginning with a March 2021 firmware build, affected devices produced seeds with roughly 72 bits of entropy instead of the expected 128 bits, allowing attackers to brute-force and recreate private keys at scale — entirely offline. Losses have been estimated at up to $130 million in Bitcoin.

Which Coldcard models and firmware versions are affected?

Per Coinkite’s advisory: Mk2/Mk3 firmware versions 4.0.1 through 4.1.9 (March 2021 onward); Mk4 and Mk5 firmware before standard 5.6.0 or Edge 6.6.0X; and the Coldcard Q before standard 1.5.0Q or Edge 6.6.0QX. Seeds generated on affected devices without additional user-supplied entropy may be at risk.

I never shared my seed phrase and my device never went online. How was I robbed?

That is exactly what makes this flaw so serious. The weakness was inside the device’s firmware at the moment your seed was created. Because the randomness was predictable, an attacker never needed your seed phrase or network access to your device — they could reproduce your private keys from the outside. Doing everything “right” did not protect owners whose seeds were generated by the defective code.

Am I protected if I used a passphrase or dice rolls?

Coinkite states that a strong, unique BIP-39 passphrase adds an independent barrier — though a short, common, patterned, quoted, or reused passphrase may be guessable. Owners who added roughly 50 to 98 independent, private dice rolls contributed at least 128 bits of entropy on their own, which protects against this specific randomness flaw.

Can I recover Bitcoin stolen in the Coldcard attack?

Recovering stolen Bitcoin directly on-chain is difficult, and as of early August 2026 roughly 90% of the stolen coins had not moved. But affected owners may have legal claims against the manufacturer and other parties responsible for the defective firmware. Peiffer Wolf is investigating those potential claims. Because deadlines may apply, affected owners should seek advice promptly.

What does it cost to talk to Peiffer Wolf?

Nothing. Consultations are free and confidential, and qualifying cases are handled on a contingency-fee basis — you owe no attorney’s fee unless there is a recovery. Call 585-310-5140 or complete an online contact form.

Get a FREE case Evaluation.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
In what products did you lose money? (Check all that apply)*
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form
This field is hidden when viewing the form

Bad Brokers in the news

Victim of Broker Misconduct? We Fight For You.