# Coldcard hardware wallets lose $30 million in rapid attack

**Published:** 2026-08-01T07:08:33.420Z  
**Topic:** Bitcoin  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/0a96c89e-19cd-4e2e-a1b5-2bbc45704b98

Coldcard wallets were hit by a 25‑minute sweep that stole $30 million from 500 wallets, exposing firmware seed vulnerabilities.

A attacker siphoned roughly $30 million from Coldcard hardware wallets in the first 10 minutes of a 25‑minute sweep that hit 500 wallets, highlighting lingering seed‑generation flaws in the device’s firmware [2].

| At a glance | |
|---|---|
| Amount stolen (first 10 min) | $30 million |
| Total sweep value | $38 million+ |
| Wallets affected | 500 |
| Primary catalyst | Targeted large‑balance Coldcard wallets |

## Attack mechanics and scale  
Chainalysis reported that the perpetrator prioritized the largest Coldcard wallets, extracting $30 million within ten minutes before expanding to smaller balances. Three of the ten biggest victim wallets each held at least 10 BTC (≈ $636 k per wallet at the time) [2]. The operation continued for about 25 minutes, ultimately draining 500 distinct wallets and pushing the total value taken past $38 million. The pattern suggests the attacker pre‑mapped the wallet population to maximize early gains rather than proceeding randomly.

## Vulnerabilities and response  
The breach exploited seeds generated on vulnerable firmware, a risk that persists even after applying the hotfix released by Coldcard. Bitkey’s engineering lead, Clay Garrett, noted that the attacker used a paid account with a major blockchain‑services provider to query source addresses, enabling the precise targeting of high‑balance wallets [2]. Although the provider supplied standard services, the specificity of the requests helped investigators trace the operation, underscoring the importance of securing both hardware and the ancillary services used for address look‑ups.

## What to watch
- **Firmware updates** – Monitor Coldcard’s release notes for any further patches addressing seed generation.  
- **Large‑balance wallet activity** – Watch for unusual outbound flows from wallets holding ≥ 10 BTC, especially on the Bitcoin network’s mempool.  
- **Blockchain‑service provider logs** – Any anomalies in query patterns from known service accounts could signal repeat targeting.

The incident demonstrates that even “offline” cold storage can be compromised through firmware weaknesses and external query services, raising questions about the long‑term resilience of hardware wallets without rigorous seed‑generation safeguards.

## Sources
1. Investopedia — [investopedia.com/news/bitcoin-safe-storage-cold-wallet](https://www.investopedia.com/news/bitcoin-safe-storage-cold-wallet/)
2. News — [Coldcard Attacker Stole $30M in 10 Minutes by Targeting Big Wallets](https://news.bitcoin.com/security/coldcard-attacker-stole-30m-in-10-minutes-by-targeting-big-wallets/)

---
Cite as: TrendWatcher, "Coldcard hardware wallets lose $30 million in rapid attack", https://www.trendwatcher.in/article/0a96c89e-19cd-4e2e-a1b5-2bbc45704b98
