The Bitcoin hardware wallet attack on Coldcard devices has drained more than 1,000 BTC, worth approximately €64 million (around $70 million), from roughly 1,200 wallets in a single 41-minute sweep on 30 July 2026, according to blockchain analysis from Galaxy Research. Every Coldcard Mk3 owner who generated a seed after March 2021, along with Mk4, Mk5 and Coldcard Q users who set up their device before the emergency patch, must update firmware immediately and move funds to a newly generated wallet. Coinkite, the Canadian manufacturer behind Coldcard, has confirmed the root cause was a firmware flaw that silently weakened private key randomness for more than five years before attackers exploited it.

For European Bitcoin holders, who make up a substantial share of global self-custody users, this is not a distant story. It is an urgent, time-sensitive security event with direct financial consequences and no regulatory safety net if funds are lost.
Coldcard Wallet Attack Overview
On 30 July 2026, an attacker or coordinated group drained 1,196 Coldcard-linked Bitcoin addresses of 1,082.65 BTC, worth about $70 million, in a 41-minute window, according to Galaxy Research's on-chain reconstruction reported by CoinDesk on 1 August 2026. Initial reporting on 31 July 2026 had put losses at roughly $38 to $40 million from around 500 to 594 devices; that figure was revised sharply upward as investigators mapped the full scope of the sweep.
Coinkite founder Rodolfo Novak publicly apologised on 31 July 2026, stating the company took full accountability for the firmware failure: "I'm sorry and I'm devastated. Our team is heartbroken about yesterday's news." He noted that the review process which should have caught the bug had failed, and suggested that modern, AI-assisted code review tools are now able to surface latent bugs of this kind faster than manual audits historically could.
The Vulnerability: How the Attack Unfolded
A firmware integration error introduced in Coldcard's version 4.0.0 update in March 2021 is the root cause of the Coldcard vulnerability. It silently rerouted seed generation away from the device's dedicated STM32 hardware random number generator and into a predictable software fallback, weakening the randomness protecting users' private keys for more than five years without detection.
Instead of drawing entropy from a certified hardware source, affected devices generated seeds using a deterministic software pseudorandom number generator seeded largely from the chip's factory-fixed serial number and its clock registers. Both values are either fixed or narrowly guessable, meaning an attacker with a Coldcard of their own could feasibly reconstruct the possible seed space.
Coinkite's own technical review estimated that affected Mk3 devices generated seeds with only around 40 bits of effective entropy, and that Mk4, Mk5 and Q models, which draw partial randomness from a secure element, fared better but still fell to roughly 72 bits. Both figures sit far below the 128-bit standard considered cryptographically safe, which explains how a well-resourced attacker was able to enumerate and sweep more than a thousand affected wallets in under an hour.
Per Coinkite's security advisory, updated 1 August 2026, funds controlled by any seed generated on a Mk2 or Mk3 device running firmware 4.0.1 through 4.1.9 (March 2021 onward) are considered at risk, unless that seed was created using at least 50 fair, independent dice rolls rather than the device's own generator.
Immediate Actions: What Coldcard Users in the EU Must Do
EU-based Coldcard owners must do two separate things: install the corrected firmware, and generate a brand new seed to move funds into, since the firmware update alone does not repair a seed that was already created under the flawed randomness.
- Mk2/Mk3 users: update to firmware version 4.2.0 or later.
- Mk4/Mk5 (standard) users: update to version 5.6.0 or later.
- Coldcard Q (standard) users: update to version 1.5.0Q or later.
- Mk4/Mk5 and Q Edge variants: update to version 6.6.0X / 6.6.0QX or later.
- After updating, generate a completely new seed on the device rather than reusing the old one.
- Send a small test transaction to the new wallet first, verify receipt, then migrate remaining funds in stages.
- Keep the old backup seed accessible but do not add new funds to it until migration is fully complete.
Owners who set up their original seed using at least 50 independent dice rolls, rather than relying on the device's built-in generator, are not considered at risk and may treat the firmware update as precautionary rather than urgent. Everyone else should treat migration as time-critical, since the underlying weakness has now been public and actively exploited since late July 2026.
Securing Your Crypto: Best Practices for Hardware Wallets
The strongest immediate protection for an at-risk seed, short of full migration, is a strong, unique BIP-39 passphrase, which Coinkite confirms adds meaningful protection even though it does not remove the need to eventually migrate. Beyond this incident, several habits meaningfully reduce hardware wallet risk for EU holders.
- Only install firmware downloaded directly from the manufacturer's official site and verify its cryptographic signature before flashing it to the device.
- Where balances are significant, use a multisignature setup spread across two or more independent hardware wallet brands, so a single-vendor firmware flaw cannot compromise the whole balance.
- Avoid trusting a single device's internal randomness for large holdings; supplement or replace it with manually rolled dice entropy where the device supports it.
- Periodically test that recovery seeds actually restore the correct addresses on a second, offline device.
- Treat any wallet that has held a large balance since before August 2026 firmware corrections as a candidate for precautionary migration, even outside the Coldcard ecosystem.
Impact on the Broader Cryptocurrency Market in Europe
The Coldcard breach lands at a moment when crypto ownership across the euro area is already substantial and growing. According to the European Central Bank's Consumer Expectations Survey (data referenced November 2024), an average of 9.7% of euro area households reported owning crypto-assets. Separately, the ECB's Financial Stability Review from May 2025 recorded that euro area investors held €17 billion in crypto-asset-related investment products in the fourth quarter of 2024, of which households alone accounted for roughly €10 billion, or 59% of the total.
This incident also exposes a genuine regulatory gap that most coverage has overlooked. The EU's Markets in Crypto-Assets Regulation (MiCA) became fully enforceable across all 27 member states on 1 July 2026, creating a harmonised licensing and consumer protection regime for Crypto-Asset Service Providers such as exchanges and custodians. However, MiCA governs regulated intermediaries, not self-custody hardware wallets. A Coldcard user holding their own keys is not a customer of a licensed CASP in the way an exchange user is, so the compensation and conduct obligations MiCA imposes on licensed firms simply do not apply to a firmware failure inside a hardware device. For readers following broader finance coverage of the EU's crypto framework, this is the practical limit of MiCA: it protects consumers of regulated platforms, not the growing number of Europeans who deliberately moved their coins off exchanges specifically to avoid platform risk.
The social impact of that gap is direct. Self-custody is disproportionately popular among long-term retail holders, retirees supplementing pension income, and small-business owners in countries such as Germany, the Netherlands and Spain who moved funds off exchanges after previous custodial collapses. For a household with several years of savings concentrated in a single Coldcard wallet, an entropy flaw of this kind can mean an irreversible, uninsured loss of life savings within minutes, with no ombudsman, deposit guarantee scheme or MiCA-based complaints process available, because no licensed EU entity was ever holding the funds. That is a materially different risk profile from a bank account or a regulated brokerage, and it is one EU savers considering self-custody should weigh carefully alongside its genuine security advantages.
Practical Checklist: What to Do Today
- Check your Coldcard model and firmware version now, before doing anything else with the device.
- If you are on Mk2/Mk3 firmware 4.0.1 to 4.1.9, or any pre-patch Mk4, Mk5 or Q firmware, assume migration is necessary unless your original seed came from at least 50 independent dice rolls.
- Update to the corrected firmware version listed above directly from Coinkite's official channels.
- Generate a new seed, send a small test transaction, confirm receipt, then migrate the remainder of your holdings in stages.
- Add a strong, unique BIP-39 passphrase as an interim safeguard while migration is in progress.
- For balances above a few thousand euros, consider splitting custody across a multisignature setup using more than one wallet manufacturer going forward.
Readers researching wider digital asset protection strategies can also see related EU financial security coverage on Baba International for context on how European regulation is adapting to self-custody risk.
Baba International Editorial Team
Our editorial team specialises in UK and EU personal finance, health policy, and economic analysis. All content is researched using authoritative sources including the ONS, NHS, Bank of England, ECB, and Eurostat.
Related Reading
- UK Crypto Regulation: How the FCA's New Stance Impacts Retail Investors
- EUR/USD Exchange Rate Today: What Eurozone GDP Data Means for the Euro
- MiCA Stablecoin Rules: What EU Investors Need to Know
- Europe's Proteinmaxxing Trend: What it Means for Infant Formula Prices Today
Frequently Asked Questions
Which Coldcard models are affected by this attack?
Coldcard Mk3 devices running firmware 4.0.1 through 4.1.9 (installed from March 2021 onward) are confirmed at risk. Mk4, Mk5 and Coldcard Q devices are also affected if their seed was generated before the corrected firmware was installed, though their effective entropy loss is smaller at roughly 72 bits rather than the 40 bits estimated for Mk3.
Is updating the firmware enough to protect my funds?
No. Updating firmware prevents new seeds from being generated insecurely, but it does not repair a seed that was already created under the flawed randomness. Coinkite's advisory instructs affected users to generate an entirely new seed after updating and migrate funds to it.
Are EU Coldcard users protected under MiCA if their funds are stolen?
No. MiCA regulates licensed Crypto-Asset Service Providers such as exchanges and custodians, not self-custody hardware wallets. Since Coldcard users hold their own private keys rather than depositing funds with a regulated firm, MiCA's consumer protection and compensation provisions do not apply to losses from a hardware wallet firmware flaw.
How can I check if my seed was generated during the vulnerable period?
Check the firmware version your device was running when the seed was first created, not the version currently installed. If that version falls within Mk2/Mk3 4.0.1 to 4.1.9, or any pre-patch Mk4, Mk5 or Q release, and the seed was not generated using at least 50 independent dice rolls, Coinkite recommends treating it as at risk and migrating to a newly generated seed.
Comments
Post a Comment