“Has Coldcard been hacked?” has a lazy answer and a precise one. The lazy answer — from fans, “never,” and from headline-skimmers, “yes, for $88 million” — is wrong in both directions. The precise answer requires splitting one word, hacked, into four different claims, because Coldcard’s record contains all four: laboratory attacks that never hurt anyone, firmware bugs fixed before exploitation, a company-data story that is routinely misreported, and — since July 30, 2026 — the single worst verified loss event in hardware-wallet history. This page is the verified record, each item labeled with what an attacker actually needed and whether it is fixed today.
TL;DR. No Coldcard has ever been broken into remotely — but yes, in July 2026 Coldcard users suffered the worst verified loss event any hardware wallet has produced, and it earned the word “hack” in every practical sense. From March 2021 to July 2026, a one-line firmware bug silently replaced the hardware random number generator with a predictable software PRNG, so seeds generated on affected firmware could be brute-forced entirely offline, with zero access to the device. On July 30, 2026, attackers swept ≈1,082.65 BTC (≈$70.2M) from 1,196 addresses in 41 minutes; tracked losses grew to ≈1,367 BTC (≈$88.6M) across 4,585 addresses over three waves, per Galaxy Research — figures still evolving. The device wasn’t hacked; the seeds were born predictable. A firmware update alone does not fix an existing seed — affected users must generate a new seed on fixed firmware (Mk3 4.2.0+, Mk4/Mk5 5.6.0+, Q 1.5.0Q+) and migrate. Everything else in Coldcard’s history is lab attacks requiring physical possession, or remote-class bugs patched before known exploitation. No confirmed breach of Coinkite’s servers has ever occurred, and no counterfeit Coldcard hardware has ever been documented.
The event you actually heard about: July 30, 2026
When someone asks this question in August 2026, they almost always mean one thing: Coinkite’s July 30 advisory (updated August 1) and the on-chain sweeps that landed the same day.
The mechanics are almost embarrassingly small. In March 2021, a firmware migration switched Coldcard’s seed generation off the STM32 chip’s hardware true-random-number generator and onto MicroPython’s deterministic Yasmarang software PRNG — because a build flag was set to 0 and the code checked whether the flag was defined instead of what its value was. One preprocessor line. Block’s engineers, working with anonymous researchers after reports from affected users, found it five years later; nobody had noticed in the interim, despite open source and reproducible builds. The result, per Coinkite’s entropy backgrounder: seeds generated on Mk2/Mk3 firmware 4.x carried roughly 40 bits of effective entropy, and seeds on Mk4/Mk5 before 5.6.0 and Q before 1.5.0Q roughly 72 bits — against an intended 128. (Block’s own enumeration estimates run lower still — as little as ≈2^16 of work for Mk2/Mk3, and at most ≈2^32 for the later models.) (One caveat worth keeping: Coinkite’s advisory dates the affected range from 4.0.1, Block says the regression shipped in 4.0.0 — so the safe phrasing is any Mk2/Mk3 seed generated on firmware 4.x before 4.2.0.)
Forty bits is a weekend of computation. Attackers enumerated candidate PRNG output streams offline, derived addresses, and checked them against the public blockchain — no device access, no malware, no phishing, no user error. On July 30, between 01:10 and 01:51 UTC, Galaxy Research tracked 1,082.65 BTC (≈$70.2M) drained from 1,196 addresses in 41 minutes. Over three waves the tracked total grew to ≈1,367 BTC (≈$88.6M) across 4,585 addresses — and Galaxy said the attack was ongoing, so treat every total as a snapshot, not a final score. Wave-one figures even differ across outlets — CoinDesk reported ≈594 BTC over 25 minutes for wave one where Galaxy tracked 1,082.65 over 41 — and Coinkite’s own advisory cites no theft figures at all; the loss attribution is Galaxy and Block analysis.
Three things this event is not, because the conflations are everywhere: it is not a remote break-in of the device (nothing ever connected to any Coldcard); it is not a Coinkite server breach (none has ever been confirmed — more below); and it has no CVE number — if you see one cited, it was invented. And the sentence that matters most, straight from the advisory: updating firmware does not repair a seed that already exists. Affected users must update, generate a new seed on fixed firmware, verify the backup and a receive address, send a test transaction, and migrate. Seeds made with 50+ private dice rolls, and funds behind a strong unique BIP-39 passphrase, are not at risk from this flaw alone; TAPSIGNER, OPENDIME and SATSCARD are unaffected.
On July 31 — about 24 hours after disclosure — Coinkite shipped fixed firmware for every model, including a new 4.2.0 build for the discontinued Mk2/Mk3. CEO Rodolfo Novak apologized, said he takes “full accountability for the firmware bug,” admitted review had failed, and urged users to move funds. Two honesty notes on the aftermath: his remark that AI likely found the bug is speculation, not established fact — no concrete evidence has been published — and no compensation or reimbursement commitment exists in any official post as of early August 2026. A formal technical review has been promised but not yet published.
The rest of the record, item by item
The 2026 disaster deserves its own section; the rest of Coldcard’s history deserves honest sorting. The sorting key is always the same question: what did the attacker need?
Remote-class firmware bugs, 2019–2021 — fixed before known exploitation
These required a compromised computer, not a stolen device — the same threat class as the 2026 flaw’s exploitation, which is why they matter:
- Dec 2019 — multisig PSBT tampering. Firmware 3.0.6 fixed an issue letting a man-in-the-middle tamper with multisig transactions to steal funds; Coinkite told users to upgrade ASAP. Fixed; historical.
- Jun 2020 — BIP-143 double-sign. An industry-wide SegWit issue where host malware could trick a user into signing twice, burning coins as fees. Coldcard shipped detection within days in 3.1.4. Fixed; historical.
- Nov 2020 — isolation bypass. Disclosed by Shift Crypto’s benma: a compromised computer could present a mainnet transaction as testnet, tricking the user into signing real BTC away. Coinkite initially claimed it wasn’t affected, shipped the fix only as a beta past the 90-day embargo, and publicly downplayed the severity. Fixed; historical — but note the handling.
- Feb 2021 — multisig xpub substitution. Disclosed by Nunchuk’s Hugo Nguyen and benma: during multisig setup, the Coldcard never verified it owned one of the registered keys, so a compromised host could substitute attacker keys into the wallet. Fixed silently in 3.2.1, acknowledged as a security fix only after public disclosure; the researcher’s bounty request was ignored. Fixed; historical.
- Jul 2026 — amount spoofing. Firmware 5.5.1/1.4.1Q fixed a legacy-input amount-spoofing issue, weeks before and separate from the entropy event. Fixed.
The pattern worth naming: every one of these was fixed before any known exploitation — and Coinkite’s 2020–2021 instinct was to downplay and quiet-patch, a documented contrast with its fast, contrite 2026 response.
Laboratory attacks, 2020 and 2023 — physical possession, no victims ever
- May 2020 — Mk2 PIN extraction. Ledger’s Donjon lab desoldered the Mk2’s secure element, milled the package, and used laser fault injection — roughly $200k of equipment — to recover the pairing secret and PIN hash. Unfixable on the Mk2 (silicon-level); the Mk3’s upgraded chip was not affected. Nation-state-class, per Coinkite. No real-world exploitation ever reported.
- Sep 2023 — Mk4 SE2 fault. Donjon laser-faulted one of the Mk4’s two secure elements after destructive chip removal — and still never reached the seed, which lives in SE1, encrypted such that compromising SE1, SE2 and the MCU together is required. Coinkite published the result itself as validation of the dual-chip design. No known master-seed extraction from any Mk3-or-later Coldcard has ever been published.
A lab attack that needs your specific device in hand, a chip lab, and six figures of equipment is a different universe from a flaw exploitable against everyone at once from a laptop. Both are worth knowing about; only one has ever cost anyone money.
The two side stories people conflate with “hacked”
- June 2026 — paper-letter phishing. Fraudulent physical letters impersonating Coinkite (and competitors) pushed a fake quantum-scare firmware upgrade via QR codes leading to counterfeit Coinkite websites that asked for PINs and seeds. Coinkite audited its servers and found no breach, attributing addresses to aggregated third-party industry leaks — and reminded customers it never sends paper letters. This is also the only “counterfeit Coldcard” on record: fake websites, never fake hardware.
- August 2026 — email retention. Advisory emails revealed that Coinkite still holds buyer emails going back to 2019, despite its CEO’s earlier claim that customer data was erased about 90 days after purchase; the company admits it has no deletion schedule. This is a data-retention controversy — a broken privacy promise, not a break-in. No confirmed breach of Coinkite’s servers exists anywhere in the 2019–2026 record.
The honest scoreboard: every vendor has a record
Here is where this page has to be careful, because this site earns commission on Trezor links, and the cheap move would be to let the Coldcard section above do the selling. So let’s put Trezor’s record on the same table, with the same rigor.
Trezor’s published attack history is longer than Coldcard’s: the wallet.fail seed extraction at 35C3 (2018); Donjon’s ≈$100 board that pulled a seed from a stolen Trezor One or Model T in about five minutes (2018, architecturally unfixable on those models); a power-analysis PIN recovery (fixed in firmware, 2019); Kraken’s voltage-glitch attack (2020, ≈15 minutes of physical access, silicon-level); Unciphered’s Trezor T extraction (2023 — Trezor’s CTO confirmed it’s substantially the same silicon flaw Kraken found); a Donjon supply-chain-implant scenario on the Safe 3 (2025 — realistic victim: someone buying second-hand or from an unauthorized seller; Safe 5 not affected; resolved); and a Donjon laser fault against the Safe 7’s brand-new secure element (2026 — funds not at risk because PIN, backup and keys are split across three independent chips; firmware mitigation shipped, hardened silicon due late 2026).
Count the entries and Trezor “loses.” But the records differ in class, not just count, and class is what empties wallets:
- Every single published Trezor seed extraction requires physical possession of the device (or supply-chain interception before it reaches you). Every one is defeated by a strong BIP-39 passphrase — Trezor’s consistent answer, and the honest reason this site’s guides bang on about passphrases. None has ever been linked to mass on-chain theft.
- Coldcard’s physical findings are milder (a PIN on a retired chip; a secondary chip faulted without reaching the seed) — but Coldcard produced the only remote, zero-touch flaw in hardware-wallet history that actually drained wallets at scale.
- Trezor devices are not affected by the 2026 entropy bug. That’s a statement about this bug, not a halo: any vendor can ship a generation flaw, which is why what survives both failure classes matters most — a strong unique passphrase, user-supplied dice-roll entropy, and, for large sums, multisig across different vendors.
Mandatory disclosure while reading any of this: most Trezor findings and both Coldcard physical findings came from Ledger’s Donjon — a direct commercial competitor of both (both vendors confirmed the research; Trezor pays Donjon bounties). The 2026 Coldcard root cause, by contrast, came from Block, and the loss data from Galaxy Research — neither a hardware-wallet competitor — making it the cleanest-sourced item on this page.
What this means if you’re choosing a wallet today
Threat-model the record instead of vibing it. If your risk is a burglar or a border crossing — someone physically taking the device — the lab-attack rows matter, and the answer on every brand is the same: current-generation secure-element hardware plus a passphrase. If your risk is remote and scaled — the class that actually produced victims — the 2026 lesson is that the seed’s birth is everything: generated on current firmware, on hardware whose supply chain you didn’t take on faith, with entropy you can optionally supply yourself via dice.
That last clause is why the boring purchase advice keeps winning: buy new, direct from the maker. A used device stacks unverifiable history on top of whatever the vendor’s record already holds — the full argument is in is a used hardware wallet safe, and if you’re buying from Thailand, the channel-by-channel version is in buying a Trezor in Thailand. Note that the one realistic Trezor Safe 3 attack scenario (the 2025 supply-chain implant) and the used-device scam catalog point at the same mitigation. And whatever you run today, put your addresses on a watch-only alert — Watchtower exists because the first sign of a compromised seed is an on-chain movement, and July 30 gave 4,585 addresses that lesson at once.
Where do I land personally? My daily recommendation was Trezor before July 2026 and still is — but the reasons haven’t changed, and none of them is “Coldcard got hacked.” Current-generation secure elements, fully open source, passphrase support that neutralizes the entire physical-attack class, and a price that doesn’t punish starting small. If your threat model differs, run it through the hardware wallet picker — six questions, no brand loyalty — and the Safe 3 vs Safe 5 comparison settles the entry-level question head-to-head. Standard disclosure applies: this site earns a commission on the link below; the record above doesn’t care who profits.
FAQ
Is my Coldcard safe right now?
Firmware version today is the wrong question; seed origin is the right one. Seeds generated on Mk2/Mk3 firmware 4.x before 4.2.0, Mk4/Mk5 before 5.6.0, or Q before 1.5.0Q are predictable and actively being swept — treat them as compromised. Update, generate a new seed on fixed firmware, test, migrate. Dice-roll seeds and passphrase-protected funds are outside this flaw; TAPSIGNER/OPENDIME/SATSCARD unaffected.
Was the device actually hacked remotely?
No device was ever touched. The seeds were generated with ≈40 or ≈72 bits of effective entropy instead of 128, and attackers brute-forced them offline against the public blockchain. That’s worse than a device hack in one way — it needed no access to anything — and it’s why a firmware update can’t repair a seed that already exists.
Should I switch brands?
You’re migrating to a new seed either way, so it’s a fair moment to choose hardware fresh. Weigh classes, not counts: Trezor’s longer list is all physical-access, passphrase-mitigated, zero mass theft; Coldcard’s shorter list contains the one flaw in history that drained wallets remotely — answered by a fast, accountable fix. Whatever you pick: new, direct, current generation, with a passphrase.
Is counterfeit Coldcard hardware a thing?
No documented case exists, 2019–2026. The only counterfeits on record are fake Coinkite websites linked from fraudulent paper letters in mid-2026 — a phishing campaign, explicitly not a Coinkite breach. No vendor sends paper letters about firmware, and nothing legitimate ever asks for your seed.
Lab attack vs. real-world hack — why do you keep splitting hairs?
Because prerequisites are the whole story. No physical lab attack — $200k laser rig included — has ever been traced to documented mass theft on any brand, though a stolen, passphrase-less device from the unfixable-extraction era can’t be assumed safe; that’s exactly why the passphrase advice exists. A predictable-seed flaw exploitable from a laptop produced ≈$88.6M of tracked theft in days. Headlines price both the same; your threat model shouldn’t.
What would make you change this assessment?
Checkable events: Coldcard’s promised technical review not appearing or contradicting the disclosure; another generation-class flaw anywhere; any current-generation Safe-series seed extraction without physical access; any verified real-world theft traced to a Trezor vulnerability. Theft totals cited here are Galaxy Research tracking as of early August 2026 and still evolving — we update dated claims as the record moves.
Related reading
- Ledger vs Trezor vs Coldcard — the long-form three-vendor argument
- Trezor Safe 3 vs Safe 5 — the entry-level decision, head-to-head
- Is a used hardware wallet safe? — why device history is the risk you can’t audit
- Buying a Trezor in Thailand — the channel question, solved locally
- Hardware wallet picker — six questions, a shortlist for your threat model
- Bitcoin Watchtower — watch-only movement alerts, because on-chain is where compromise shows first