Key Takeaways
- Over $130 million in Bitcoin has been stolen through a firmware vulnerability affecting Coldcard hardware wallets across several attack campaigns
- Daily Bitcoin active addresses reached 980,000, marking the highest level since December 2024, primarily due to security-driven asset movements
- Security analysts have identified at least 15 distinct attackers who leveraged the weakness, with indications of a fourth attack wave
- Stolen cryptocurrency totaling 64 Bitcoin and 200 Ether has been transferred to mixing platforms Wasabi and Tornado Cash for laundering
- This Coldcard breach represents the third-most significant cryptocurrency theft in 2026 to date
A critical security weakness in Coldcard hardware wallets has unleashed one of 2026’s most significant Bitcoin security breaches, with total losses now surpassing $130 million.
The security flaw originated from a firmware defect introduced in March 2021, which compromised the randomness of seed phrase generation on impacted devices. This weakness reduced cryptographic key strength from a secure 128 bits down to a vulnerable 40 bits, enabling attackers to crack wallets through brute force methods without requiring physical device access.
Galaxy Digital’s investigation has verified at least three distinct attack campaigns, successfully draining cryptocurrency from 7,300 compromised wallets. Evidence suggests a potential fourth attack wave may be underway, which could drive cumulative losses significantly higher.
Network Activity Surges Following Security Breach
According to blockchain intelligence provider Glassnode, Bitcoin active addresses climbed to approximately 980,000 daily transactions in the aftermath of the exploit. This represents the highest activity level observed since December 2024.
Glassnode emphasized that this network activity increase stemmed from security concerns rather than bullish market sentiment. The analytics firm characterized the surge as “an operational security response, not a change in market conviction.”
Previously dormant Bitcoin holdings valued at nearly 200 times the original theft amount became active on the network, indicating widespread precautionary measures by cryptocurrency holders moving their assets to safer storage.
The initial July 31 compromise involving 594 Bitcoin, valued at approximately $38 million during the theft, catalyzed the broader network security response. Galaxy Research subsequently verified that total losses had escalated beyond 1,596 Bitcoin, representing over $100 million in value.
Stolen Cryptocurrency Funneled to Privacy Services
Blockchain security company CertiK has been monitoring the movement of compromised assets. Their analysis revealed that approximately 64 Bitcoin, valued at $4.17 million, was transferred to Wasabi, a Bitcoin privacy-enhancing protocol. Additionally, 200 Ether worth roughly $380,000 was channeled through Tornado Cash.
CertiK analysts believe some transactions may originate from opportunistic secondary attackers. “We think it might be a smaller exploiter. There’s likely a few copycats after the initial exploit,” a CertiK representative explained.
TRM Labs analysis indicates the majority of stolen cryptocurrency remains consolidated in a limited number of attacker-controlled addresses. Variations in attack methodology across different waves suggest the involvement of at least 15 independent threat actors.
Dragonfly managing partner Haseeb Qureshi observed that certain artificial intelligence models successfully identified the underlying security weakness in under 20 minutes. He estimated that approximately two dollars worth of AI-assisted security testing could have prevented this exploitation.
Cybersecurity professionals warn that merely updating firmware provides insufficient protection for compromised users. Anyone who initialized a wallet on an affected device should immediately generate a new wallet on secure hardware and transfer all assets.
This Coldcard security breach currently stands as the third-largest cryptocurrency theft recorded in 2026.



