Coldcard Hack Triggers Historic Bitcoin Exodus as ETF Inflows Continue

Isometric Bitcoin symbol with golden rim light floating amid frosted panels and wallet icons on dark background

Tokens mentioned in this article:

Loic Dos Santos | BITCOIN | 2 days ago

Coldcard Chaos Triggers Historic Bitcoin Exodus A critical vulnerability in the Coldcard hardware wallet has shaken the Bitcoin ecosystem, prompting a wave of panic among long-term holders.

Coldcard Chaos Triggers Historic Bitcoin Exodus

A critical vulnerability in the Coldcard hardware wallet has shaken the Bitcoin ecosystem, prompting a wave of panic among long-term holders. Over the past week, approximately 210,000 BTC—worth more than $13 billion at current prices—were transferred out of wallets that had previously remained dormant for months or even years. This marks the largest exodus from so-called long-term holder (LTH) wallets since December 2024, with the total LTH supply dropping from just under 15 million BTC to about 14.7 million BTC after the incident.

The breach exposed thousands of addresses to potential theft, and on-chain data shows a flurry of transactions as users scrambled to secure their funds. Glassnode, an analytics firm, defines LTHs as entities whose coins have not moved for at least 155 days—a threshold easily surpassed by many of the compromised wallets in this event. The scale of this movement is unprecedented for a single hardware wallet exploit.


Thousands of Coldcard addresses were affected, with estimated losses reaching $114 million according to DefiLlama’s hack tracker.

How Weak Code Opened the Vaults

The root cause was traced to weak randomness in certain Coldcard firmware versions, specifically affecting devices running firmware starting with version 4.0.1 released in March 2021. Instead of relying on a secure hardware-based random number generator to create wallet seeds—the cryptographic phrases that protect Bitcoin holdings—the affected firmware used a flawed software generator. This oversight allowed attackers to reconstruct some users’ recovery phrases and drain their wallets.

Coinkite, the Canadian company behind Coldcard, acknowledged that the bug “silently went unnoticed” for years and urged users to generate entirely new wallets rather than simply updating their firmware. The company emphasized that updating software alone cannot protect keys already compromised by weak seed generation.

Victims Left Scrambling for Safety

For many, the attack was devastatingly personal: individual victims reported a median loss of just over 1 Bitcoin (roughly $65,000), with some losing as much as 58.97 BTC in a single theft. Analysis of 250 victim reports found that most stolen coins had been untouched for at least a year—88% fell into this category—and typically sat idle for about three and a half years before being swept away by hackers.

One victim lost nearly $4 million in a single transaction.

The exploit unfolded in multiple waves. Galaxy Digital tracked three confirmed attack waves affecting at least 7,300 wallets and estimated losses between $100 million and $130 million in Bitcoin alone; DefiLlama’s hack tracker put losses at around $115 million. A suspected fourth wave may push totals even higher. On paper, hardware wallets are supposed to offer maximum security—but this incident revealed how a single software flaw can undermine years of careful self-custody.

Second-Worst Month for Crypto Thefts

The Coldcard breach contributed heavily to July 2026’s grim tally of crypto losses: $247.4 million was stolen across various exploits, making it the second-worst month for crypto thefts so far this year according to DefiLlama data. Only April saw greater carnage, with $644 million lost to hackers and scammers across the digital asset landscape.

Other July attacks included $24 million siphoned from AFX and $9 million from Bonzo Lend, but none matched Coldcard’s scale or impact on user trust. In June and May combined, total crypto thefts were less than July’s Coldcard-driven sum—$75 million and $60 million respectively—highlighting how one vulnerability can skew an entire sector’s risk profile almost overnight.

ETF Inflows Defy Hack Fallout

Despite these security shocks, Bitcoin’s price remained resilient throughout the week following the Coldcard disclosure. On Friday, Bitcoin traded above $65,170—up nearly 4% compared to seven days prior—and U.S.-listed spot Bitcoin ETFs attracted over $750 million in new capital during the same period. BlackRock’s iShares Bitcoin Trust (IBIT) accounted for most inflows; Morgan Stanley’s fund also saw notable demand.

BTCUSD chart
BTCUSD : Market reading

According to bitcoinmagazine.com, investors continued buying ETF shares even as news broke that more than $111 million had been stolen from Coldcard wallets—a micro-contrast between technical insecurity and institutional appetite for exposure.

It remains uncertain whether confidence will hold if further waves of attacks emerge or if additional vulnerabilities are discovered in other popular hardware wallets.

What the next days may bring

If the suspected fourth wave of Coldcard-related attacks identified by Galaxy Digital materializes, total losses could rise to about $130 million, immediately increasing the tally of affected wallets and stolen bitcoin beyond the currently confirmed $111 million; whether additional compromised wallets will be discovered remains unclear.

About the Author

Loic Dos Santos

Editorial byline – Crypto news & marketdynamics

Editorial byline focused on analyzing crypto newsthrough market dynamics and real-world use cases. Articles under this signature provide context on announcements, sectordevelopments and their practical implications for the blockchain ecosystem.