Coinkite Coldcard Exploit- What happened and what victims should do.

Golden bitcoin coin over defocused stock chart with copy space, Olsztyn, Poland 13 July 2021

For many bitcoin holders, cold storage long represented one of the strongest forms of protection and self custody, given that private keys are generated and kept offline, outside of the typical attack vectors usually deployed by hackers. However, the recent Coldcard incident was a sobering demonstration that a hardware wallet can still be compromised and susceptible to exploitation where there is an inherent weakness embedded within the recovery seed generation mechanism.

05.08.2026

On 30 July 2026, attackers appear to have been able to exploit certain weaknesses in the way some versions of the Coldcard firmware generated wallet recovery seeds. Rather than targeting individual devices or obtaining users’ PINS, the hackers were seemingly able to recreate private keys because the underlying seeds were insufficiently random.

At the time of writing, on-chain investigations identified several waves of transactions compromising thousands of addresses, with a total estimated loss of around 1,816 bitcoin (circa £86m).

Not only does this incident raise immediate questions and concerns for Coldcard users, but also brings with it wider implications in regards to self custody, open source software, artificial intelligence, and the potential liability of hardware wallet manufacturers.

What is Cold Storage?

To understand what cold storage is, we first need to appreciate how bitcoin is held and transacted.

Bitcoin (or indeed, any other cryptoasset) is not stored in the same way cash is stored in a physical wallet, safe or bank account. Rather they exist only as entries on the relevant blockchain, for example, the Bitcoin blockchain which is a distributed ledger maintained by thousands of computers (nodes) around the world.

What gives someone control over bitcoin is not possession of the ‘coins’ themselves, but possession of the private key of the address associated with the bitcoin. A private key is a unique cryptographic code that allows the wallet address owner to authorise transactions and deal with the bitcoin associated with that address.

When you send bitcoin, you are not physically transferring coins. Rather, you are using private keys to digitally sign a transaction, instructing the Bitcoin network to update its blockchain and assign control of that bitcoin to another address.

As such, the private key is the most important thing to keep secure, as if it is compromised, anyone who obtains it can gain complete control of your cryptoassets. In other words, possession of the private key effectively equates to control of the cryptoasset it protects.

It is this importance over maintaining the integrity of private keys that leads to the concept of cold storage. By keeping those keys completely isolated from internet connected devices and networks, the aim is to minimise the attack vectors that could be exploited by hackers, malware and other online compromises. 

A popular form of cold storage is by using hardware devices, which are purpose built physical devices where private keys are kept offline. Coldcard was one such device, manufactured by Canadian company, Coinkite Inc.

When a new wallet is created, the device generates a private key, usually represented to the user by a recovery or seed phrase consisting of a sequence of words. Anyone who obtains or successfully recreates that seed phrase can normally recreate the wallet, with the private keys, and control the cryptoassets associated with it.

What happened to Coldcard wallets?

As mentioned above, a wallet generates a seed phrase, which is a human readable sequence of words which is used to derive the wallet’s private keys. The words forming this seed phrase should be generated from a sufficiently large and unpredictable pool of possible values, using a high degree of randomness known as entropy, such that simply guessing or ‘brute forcing’ private keys should be computationally impossible.

In this case, there was an inherent flaw in certain versions of the Coldcard wallet firmware, which reduced the entropy used when creating the all-important seed phrases. As a result, the seed phrases were more predictable than intended, and the attackers were seemingly able to reconstruct private keys and gain access to affected wallets.

Rather concerningly, this attack did not require physical access to the device itself or disclosure of the victim’s seed phrase. The vulnerability was effectively introduced at the at the moment the seed phrase was was generated on the previous versions of the firmware due to a flaw in the firmware’s random generation process. The significance of this is that affected users did not do anything wrong. They had followed security best practices, generated their seed phrases on a dedicated hardware wallet, and kept them private.

Perhaps most frustratingly, the relevant firmware code was publicly available on Coinkite’s GitHub repository, and although it was not open source, it was open for inspection. The vulnerability itself is thought to have entered the codebase in March 2021, but was not publicly identified until July 2026, once the exploit had already been executed.

At present, there does not appear to be any evidence which establishes how the attackers found the vulnerability, although Coinkite has suggested that AI may have been utilised to examine the earlier firmware versions and identify the issue, however, it has also confirmed that an earlier AI review of the code commissioned prior to the exploit did not identify the vulnerability.

Nevertheless, the wider concern is credible. AI systems are increasingly capable of reviewing large codebases, tracing interactions between components and identifying security weaknesses and vulnerabilities, and newer specialist AI tools are continually being developed and evolving to specifically identify complex software vulnerabilities.

Whilst these technologies are primarily intended to assist defenders by improving code quality and accelerating security reviews, the same capabilities can be deployed by attackers and a vulnerability that may have previously required weeks of painstaking manual analysis can potentially be identified far more quickly through the use of automated AI assisted tools.

What should Coldcard users do?

Anyone who has generated a seed using an affected version of Coldcard’s firmware should review Coinkite’s current security advisory urgently. The relevant question is not which firmware version is currently installed on the device, but which version was installed when the wallet seed was originally generated. If you are unsure as to whether your wallet was created on an affected version of the firmware, the prudent assumption would be that your seed is at risk.

Coinkite is advising affected users to update to the latest firmware and once the device has been updated, users should generate an entirely new seed phrase and create a new wallet. Simply installing the updated firmware will not repair the existing vulnerability as the weakness is within the seed itself.

Once a new wallet and seed has been generated, funds should then be transferred from the potentially affected wallets to addresses controlled by the newly generated seed. As a matter of good practice, a small test transaction should be performed first to ensure the backup has been recorded correctly and that the new wallet functions as expected.

Users should never, under any circumstances, disclose their seed phrase or private keys to anyone claiming that they need them to check whether their wallet is affected. Security incidents of this scale are frequently followed by impersonation, phishing and recovery scams.

What should a victim do after bitcoin has been taken?

If you have been the unfortunate victim of this exploit and have lost bitcoin, it is important to act quickly but calmly. Although bitcoin transactions cannot be reversed, the movement of bitcoin can be traced. Currently, the stolen bitcoin from the Coldcard exploit has been traced to a number of attacker controlled addresses, with over 90% of the assets remaining in those holding wallets.

While bitcoin transactions are pseudonymous, they are recorded on the public blockchain which makes it possible to follow and trace stolen assets through successive addresses and identify when they may reach a centralised custodian, exchange, bridging service or other service provider. Measured and careful steps taken at this stage can help to preserve evidence and improve prospects of recovery.

The first priority should be to secure any remaining assets. Any remaining bitcoin should be transferred immediately to a new wallet created using a freshly generated seed phrase on updated firmware or a different trusted device.

The next priority should be on evidence capture and preservation. If you are a victim of the exploit, you should take steps to record:

  • The affected wallet addresses and transaction hashes;
  • The Coldcard model and serial information;
  • The firmware version used when the seed was originally generated;
  • The approximate date when the seed was created;
  • The purchase records of the Coldcard device;
  • Any relevant screenshots, correspondence and security notifications; and
  • Any records evidencing ownership and the source of the bitcoin (i.e. purchase logs from the exchange used to purchase the bitcoin).

The next priority should be to report the theft to the Police. In England and Wales, cybercrime and fraud reports can currently be submitted through Report Fraud (formerly Action Fraud). Reporting the matter creates an official record and a crime reference number which can be useful for subsequent legal action.

Can the stolen bitcoin be recovered?

As mentioned above, it is possible to trace bitcoin transactions through the public blockchain and using a variety of attribution and open source intelligence sources, it can sometimes be possible to attribute pseudonymous wallets with their owners. It is also possible to identify when the stolen assets may have reached a centralised exchange or platform. Whilst recovery cannot be guaranteed, tools can be used to monitor the stolen assets and identify attempts to move them through exchanges or other services where there may be identification procedures.

Where there is a sufficient connection with England and Wales, for example, if the victim is resident in England, the victim may be able to pursue claims against the attackers as ‘Persons Unknown’.  The significance of the ‘Persons Unknown’ jurisdiction is that it enables victims to commence proceedings and seek urgent interim relief even where the identity of the wrongdoer is not yet known.

In appropriate cases, the court may be asked to grant:

  • A proprietary injunction preventing dealings with identified bitcoin;
  • A freezing injunction over the wrongdoer’s wider assets;
  • Disclosure orders requiring exchanges or other intermediaries to provide information about account holders and transactions; and
  • Orders permitting proceedings and court orders to be served outside the jurisdiction or by alternative means, including by serving on identified addresses via the blockchain itself.  For example, by transmitting a transaction to the relevant address containing an OP_RETURN output embedding a URL or reference directing the recipient to the court documents.

Disclosure obtained from an exchange or centralised service provider may identify the person/s controlling a destination address, reveal linked accounts or provide information about onward withdrawals. Where assets can be identified as remaining within an exchange’s control, early notification may allow for a voluntary or court ordered freeze of those accounts.

Claims against recipients or intermediaries may also be considered where there is evidence that they knowingly received or assisted in dealing with stolen assets. 

Could victims bring a claim against Coinkite?

A potential claim against Coinkite, the manufacturer of Coldcard, should not be ruled out, but it is likely to involve significant contractual, jurisdictional and evidential issues.

The central allegation would seem to be that a product marketed for the secure self custody of bitcoin generated private keys from a materially weaker source of entropy than users were entitled to expect.

Depending on the circumstances, victims may also consider claims for breach of contract and breach of consumer protection laws. It is feasible that UK consumers could argue that the Coldcard device, due to the vulnerability in the firmware which existed for a significant period of time without detection, meant that the device was not of satisfactory quality or fit for its intended purpose if the entropy defect existed at the point of sale.

There would, however, be significant legal and evidential hurdles. For example, victims would need to be able to prove that their loss resulted from the firmware vulnerability and not from phishing, malware, disclosure of the seed phrase, or another self inflicted security failure.

Victims would also need to be able to identify the correct contracting party, the terms applying when the device was purchased, and the governing law and jurisdiction. Coinkite’s current published terms seek to exclude responsibility for certain losses, limit its overall liability, and provides for any disputes to be determined in Ontario, Canada, although the effectiveness of those provisions, particularly as against UK consumers, would require careful consideration.

How we can help

The Coldcard incident presents a combination of technical, tracing and legal challenges. Victims may need to secure remaining assets, preserve forensic evidence, trace the onward movement of bitcoin across multiple jurisdictions and, where appropriate, seek urgent court relief against Persons Unknown.

Our team advises on cryptocurrency disputes, asset recovery and blockchain tracing matters. We work with specialist blockchain investigators to identify the movement of stolen cryptoassets and assist clients in obtaining urgent interim remedies, including proprietary injunctions, freezing orders and disclosure orders against exchanges and other intermediaries.

If you have been affected by the Coldcard exploit or any other cryptocurrency theft, our team would be well placed to discuss the circumstances of your case and the steps that may be available to preserve your position and maximise your prospects of recovery as the matter develops.

 

 

 

 

Key Contacts

Related Articles

  • Independent Football Regulator final rules: A practical perspective for clubs
    Expert Comment
    Independent Football Regulator final rules: A practical perspective for clubs
    The publication of the Independent Football Regulator (IFR) final rules and guidance on 1 July 2026 mark an important milestone in the implementation of the Football Governance Act 2025.
  • Financial Regulation under the Independent Football Regulator & Appropriate Financial Resources
    Expert Comment
    Financial Regulation under the Independent Football Regulator & Appropriate Financial Resources
    One of the defining features of the Independent Football Regulator ("IFR") regime is its approach to financial regulation of clubs.
  • The Independent Football Regulator - What you need to know
    Expert Comment
    The Independent Football Regulator - What you need to know
    The establishment and introduction of the Independent Football Regulator (IFR) marks a fundamental shift in how professional football in England will be governed.

Recognised for excellence. Chosen for care.

  • Legal 500 Top Tier Firm UK 202
  • alt tzt
  • Sunday Times Best Places to Work 2025