Attackers stole 594 bitcoins from owners of Coldcard hardware wallets
7/31/2026, 08:43 AM • Евгения Слив

On the night of July 31, the attackers carried out a large-scale theft of cryptocurrencies, stealing 594.48 bitcoins (about 38.2 million dollars) from about five hundred owners of Coldcard hardware wallets. Analysts of the Lookonchain platform were the first to draw attention to this incident. According to their data, the attack was carried out with high speed: the withdrawal operation took less than thirty minutes. After the transactions were completed, all the stolen coins were consolidated at a single address and had not been moved at the time of publication. The compromised wallets usually had a single signature and contained balances of over 0.15 bitcoin, while many of them remained inactive for several years, and the age of assets ranged from 2021 to 2026.
Coinkite, the developer of Coldcard devices, released an official statement on its blog, stating that the cause of the incident lies in a software vulnerability. Although the representatives of the project did not directly confirm the fact of targeted hacking of user accounts, they identified critical flaws in several generations of devices. The problem affects all firmware versions of the Mk3 model starting from 4.0.1, as well as LED phrases generated on Mk4 and Mk5 devices up to version 5.6.0, and on the Q model up to version 1.5.0Q. The development team strongly recommended that all hardware device owners update the software as soon as possible, while conducting an internal investigation into the circumstances of the incident.
This event highlights the continuing security risks associated with the use of cryptocurrency storage hardware, even from trusted manufacturers. It serves as a reminder of the growing sophistication of cyber threats targeting digital asset holders. For context, a similar large-scale incident occurred in December 2025, when the Trust Wallet browser extension was hacked. Hundreds of users were affected, and the total damage was estimated at $7 million. Such cases highlight the critical importance of timely firmware updates and compliance with strict digital hygiene protocols in the crypto industry.
