Coldcard wallet exploit losses have climbed to roughly 1,367 BTC, or about $89 million, after a third wave of coordinated Bitcoin thefts hit addresses tied to vulnerable seed generation. The latest data shows 4,585 addresses were drained between July 30 and August 1, underscoring how a single firmware defect can ripple across thousands of self-custody users.
Changpeng Zhao, widely known as CZ, used the incident to remind crypto holders that no storage method is failproof. His warning lands at a moment when many investors view hardware wallets as the gold standard for Bitcoin security.
The central issue is not only the size of the losses. It is the evolving attack pattern: the latest wave appears harder to trace, more distributed, and more efficient at sweeping smaller balances, suggesting attackers are still mining the same vulnerable key space for exposed funds.
Key Facts
- Observed losses reached about 1,367 BTC across 4,585 addresses by the morning of August 2.
- The first wave took 1,082.65 BTC from 1,195 addresses in a 41-minute period beginning at 01:10 UTC on July 30.
- A third wave moved 207.73 BTC from 1,912 addresses between 12:23 UTC on July 31 and 06:42 UTC on August 1.
- Median losses fell from 0.270 BTC in wave one to 0.010 BTC in wave two and 0.013 BTC in wave three.
- The vulnerable firmware dates back to March 2021, and updating software does not repair a seed generated on an affected device.
Coldcard Wallet Exploit
The exploit centers on a build error in certain Coldcard devices that caused wallet seeds to be generated from a software fallback rather than the hardware random-number generator. In practical terms, that made some private keys materially easier to guess than intended. For Bitcoin holders using self-custody, this is the worst-case scenario: the wallet may remain in the owner’s possession while the seed behind it is already compromised.
The attack pattern suggests an automated process rather than ordinary user transfers. Early waves funneled coins through a handful of shared collection addresses into visible single-key SegWit destinations. The third wave changed tactics. Instead of using a small set of common endpoints, each victim’s coins were routed to separate destinations, with proceeds later sitting in 293 distinct P2WSH vaults. That shift points to an operator adapting after earlier flows became easy to map on-chain.
The victims affected are not limited to large holders. In fact, the declining median theft size may be the most consequential detail for the market. Attackers appear willing to spend hours sweeping wallets worth only a few thousand dollars, indicating that exposed balances no longer need to be large to become targets. That broadens the population at risk from high-net-worth Bitcoin holders to ordinary long-term savers, early adopters, and retail investors who may have assumed smaller balances were beneath attention.
“Nothing is 100%” is the clearest takeaway from the Coldcard wallet exploit: even trusted hardware can become a single point of failure when seed generation is compromised.
How the theft pattern evolved
On-chain behavior reveals a notable progression. Wave one took nearly a full coin per victim on average and processed one address at a time, while later activity became more selective and more industrialized. In wave three, the sweeper batched an average of 6.37 victims per transaction and appears to have scanned only the default derivation path instead of exploring multiple branches per seed.
Fee behavior also changed across the waves, moving from 30 sat/vB in wave one to mixed levels in wave two and roughly 200 then exactly 10 in wave three. That may indicate the same operator refining an automated tool after public scrutiny, or a second actor exploiting the same weakness independently. Either way, the evidence suggests the profitable portion of the vulnerable key pool may be thinning, but the scanning activity had not stopped after three days.
Coinkite co-founder Rodolfo Novak acknowledged the bug and said emergency hotfixes were shipped. He also warned that installing the update does not secure seeds already created on affected firmware. For exposed users, the remedy is not simply patching a device; it is generating an entirely new seed on safe firmware or new hardware and moving funds to fresh addresses.
Implications for Investors
For Bitcoin investors, the incident is a reminder that self-custody risk is not binary. Hardware wallets reduce online attack surfaces, but they do not eliminate manufacturing, firmware, supply-chain, or implementation risk. Investors with concentrated BTC holdings in a single-signature setup may need to revisit whether convenience has outweighed resilience.
Portfolio protection may now require more layered custody design. Splitting assets across multiple wallets can reduce single-device exposure, but it also introduces complexity and operational risk. For larger positions, investors may consider multi-signature structures, stricter seed-generation verification, and periodic reviews of wallet provenance, firmware history, and backup procedures. The trade-off is clear: stronger security often means more process, more friction, and less simplicity.
There are also broader market implications. Events like this can temporarily undermine confidence in self-custody products, raise scrutiny on wallet manufacturers, and shift flows toward institutional-grade custodians or diversified storage models. That matters for companies exposed to crypto infrastructure, listed firms with large Bitcoin treasuries, and service providers built around retail self-custody. Investors should watch whether additional vulnerable addresses are drained, whether stolen BTC begins moving out of current holding structures, and whether other wallet vendors disclose similar seed-generation reviews.
The next phase will likely focus on remediation and chain analysis rather than immediate price impact. But the Coldcard wallet exploit has already become a defining case study in how technical defects can translate into portfolio losses long after a device was first set up.