toobit
Buy crypto
Buy cryptoThe fastest path to your first trade
P2P tradingTrade at the best prices with multiple local payment options
Bank cardPay with Visa or Mastercard
Third-partyPay via MoonPay, Advcash, Simplex, and more
DepositTransfer from another wallet
Markets
OpportunitiesTrack market sentiment and top movers
OverviewReal-time prices for all trading pairs
Futures
USDT-M PerpetualContracts settled in USDT
USDC-M PerpetualContracts settled in USDC
Event ContractsTrade on the outcome of market events
Prediction MarketTurn insights into value
Lite PerpetualSimple contracts made for easy trading
Demo TradingPractice trading in a risk-free environment
Trading BotsAutomated grid and DCA strategies
TradFi
Trading
SpotBuy and sell cryptocurrencies
DEX +Trade popular on-chain Web3 tokens in seconds
LaunchpadAccess early-stage token listings
ConvertZero-fee instant asset swaps
API TradingAutomate trading strategies with custom scripts and apps
Toobit SynapseMarket insights driven by AI analysis
Toobit x TradingViewTrade directly from TradingView charts
Agent Trade KitEquip AI agents with trading and account skills
Rewards
Copy
Follow Lead TradersCopy trades from top-performing profiles
Be a Lead TraderShare your trades and earn commissions
More
Finance
EarnPut your idle assets to work
Partnerships
Broker ProgramMonetize API volume and trading infrastructure
Ambassador ProgramRepresent the exchange and earn monthly incentives
Toobit x Nova.MemeLaunch and trade memecoins with instant liquidity
Learn
AcademyTechnical analysis and crypto trading guides
Support CenterSelf-service help and 24/7 technical assistance
Announcement CenterLatest listings, campaigns, and official product news
NewsBreaking crypto news and market moves
BlogMarket insights and exchange updates
Explore
Toobit VIP ProgramEnjoy fee discounts and many exclusive rewards.
InsightsStay updated on the latest crypto news
Toobit CommunityConnect with The Hive, our global community of traders
3 years togetherCelebrate our journey and the community that built it
About usThe story behind the award-winning exchange
Suggestions & FeedbackShare your ideas to improve the exchange
Proof of ReservesTrust built on 100% reserves
Log in
Sign up
🔥BTC/USDT
Scan to download
iOS or Android app
More download options

Coldcard exploit drains 1300 Bitcoin from wallets

2026-08-03 17:32

More than 1,300 Bitcoin has been stolen from thousands of wallets in a continuing exploit linked to a flaw in Coldcard seed generation, turning a hardware-wallet security failure into one of the largest publicly tracked losses tied to a single device vulnerability. A Monday count based on public blockchain records put the total at 1,367 BTC taken from 4,585 addresses, valued at roughly $88 million at prevailing prices.

The losses have unfolded in several waves after researchers disclosed that certain Coldcard devices could generate recovery seeds with insufficient randomness, or entropy. A seed phrase is designed to be practically impossible to guess because it should be created from a vast pool of random possibilities. The affected implementation narrowed that pool enough to make remote brute-force attempts feasible, allowing an attacker to derive wallets and drain funds without possessing the physical device.

Alex Thorn, head of research at Galaxy Digital, said researchers had identified activity consistent with as many as four waves of theft by Sunday. The first wave alone accounted for about 594 BTC, according to the latest public tally, while later sweeps pushed estimates beyond the initially reported $70 million in losses.

A flaw dating to 2021

CoinKite, the company behind Coldcard, said the issue stemmed from a firmware bug introduced in 2021. Rodolfo Novak, CoinKite’s chief executive officer, accepted responsibility for the flaw last week and described it as an example of how AI-assisted code review can uncover obscure weaknesses in public software.

The gap between the introduction of the bug and its discovery illustrates a difficult reality for open-source security: publishing code allows independent scrutiny, but it does not guarantee that every dangerous defect will be found quickly. In this case, the vulnerable code reportedly remained in official device software for more than five years before the weakness became public.

The exploit appears to target seed generation rather than the basic concept of an offline signing device. That distinction has practical consequences for affected users. A wallet created from a weak seed may remain vulnerable even if the hardware device itself is later updated, because the attacker needs only the compromised seed material to recreate the wallet elsewhere.

Moving funds to a newly generated wallet with a securely produced seed is therefore more protective than simply installing updated firmware on a device that created the original seed. Users considering any migration would need to ensure the replacement wallet is generated through an unaffected process and that the old address is not reused.

AI changes the economics of code review

Jameson Lopp, Bitcoin security researcher and co-founder of Casa, said large language models are changing how security researchers and attackers find hidden software defects. Tools that can inspect large codebases, trace possible execution paths and flag unusual patterns may lower the cost of discovering bugs that would otherwise require extensive specialist review.

That capability cuts both ways. Developers and independent auditors can use automated tools to search for weak implementations more rapidly, while attackers can use similar systems to scan public code for mistakes before a patch is released. Novak described the incident as part of a new AI-driven security environment in which latent flaws may be surfaced faster than traditional review processes anticipate.

The Coldcard episode also puts pressure on the assumption that open-source visibility alone provides adequate protection. Open code remains valuable because it permits outside review and reproducible builds, but its security depends on qualified people actually examining critical components, testing edge cases and validating the behavior of the final software distributed to users.

Lopp said verifying complex hardware and software systems remains unrealistic for nearly all users. Most people cannot independently inspect firmware, reproduce the software build, validate the hardware’s random-number generation and confirm that every component behaves as advertised. They must rely on wallet makers, developers, auditors and security researchers whose work they cannot fully reproduce.

Self-custody’s weakest link

Zach Herbert, co-founder and chief executive officer of Foundation, cautioned against treating the exploit as proof that self-custody has failed. The incident instead exposes the operational burden behind holding private keys directly: users control their funds, but the tools used to create and protect those keys can introduce risks far beyond a typical person’s ability to assess.

Hardware wallets reduce exposure to online malware and keep signing keys away from internet-connected devices, yet they also concentrate trust in several layers of technology. Those layers include firmware, chip behavior, random-number generation, manufacturing controls and the process used to distribute updates. A weakness at seed generation is especially severe because it can undermine the wallet before the user has made a transaction.

Lopp said hardware-wallet failures have occurred repeatedly, estimating that roughly a dozen significant incidents have emerged over the years. The pattern does not make hardware wallets inherently unsafe, but it argues against treating any one device, brand or setup method as infallible.

Users who suspect their wallets were created using affected software face a more immediate problem than those merely evaluating a future purchase. Funds associated with a potentially weak seed could be at risk while they remain in place, particularly after attackers have had time to identify the vulnerable wallet patterns and automate scanning.

Migration and stronger seed practices

The safest response for a potentially exposed wallet is generally to create a replacement wallet using a verified unaffected process and transfer funds to fresh addresses. Installing an update may prevent future weak seed generation, but it cannot restore randomness to a seed that was already created from a reduced entropy pool.

Generating seed material with independently verifiable randomness, such as carefully conducted dice rolls, can reduce reliance on a device’s internal random-number source. An additional BIP-39 passphrase can also change the derived wallet from a seed phrase, though users must store it securely: losing the passphrase can make their own Bitcoin permanently inaccessible.

Diversifying custody tools may reduce the chance that one vendor-specific defect places an entire Bitcoin balance at risk. It also adds complexity, which can create its own failure points. The Coldcard exploit leaves users with a less comfortable but durable lesson: offline storage protects keys from many online threats, while the process that creates those keys must be treated as a security boundary of its own.


Worried about wallet hacks? Strengthen your defenses with Toobit’s security guide, 5 ways to improve crypto safety today.

Disclaimer: The content on this page is provided for general informational purposes only and does not represent the views or financial advice of Toobit. We make no guarantees regarding the accuracy or completeness of this information and shall not be held liable for any errors, omissions, or outcomes resulting from its use. Investing in digital assets involves risk; users should independently evaluate their financial situation and the risks involved. For further details, please consult our Terms of Service and Risk Disclosure.

About
About us
Terms of Use
Privacy Policy
Risk disclosure
Toobit Community
Announcement Center
Security solutions
Toobit Shield
Proof of Reserves
Services
Trading
Futures
Copy
Affiliate Program
API
Listing application
Bug bounty
Support
Support Center
Academy
Referral
Fee rate policy
Official verification
Network monitoring
Suggestions & Feedback
Buy crypto
Buy Bitcoin
Buy Ethereum
Buy Dogecoin
Buy TON
Buy SOL
Buy XRP
Contact
Customer Support
support@toobit.com
Business
listing@toobit.com
Overview
market@toobit.com
Legal
legal@toobit.com
Apps
Google Play
App Store
Android APK
Community
TwitterMediumYoutubeDiscordRedditFacebookCoinMarketCapCoinCodexCoinGeckoLinkedinQuoraThreads
Download app
Warning

© 2026 Toobit.com. All rights reserved.