Coldcard Hardware Wallet Bug Drains $38m in Bitcoin: What UK Holders Need to Know
A five-year-old firmware flaw in Coldcard hardware wallets let an attacker drain $38m in Bitcoin from 500 wallets in 25 minutes. Here’s what UK holders should d
Nearly 600 bitcoin vanished from 500 wallets in 25 minutes last week. Not through a hack of an exchange, not through a phishing email — through a firmware bug sitting quietly inside a hardware wallet that thousands of people trusted to be the safest place for their coins.
The device is Coldcard, made by Coinkite. For years it’s been the go-to recommendation for anyone serious about Bitcoin self-custody — the kind of wallet crypto forums push on beginners asking “how do I actually keep this safe?” That reputation took a direct hit on 31 July 2026, when an attacker swept roughly 594 BTC, worth about $38 million, out of around 500 single-signature wallets in a single coordinated sweep.
When I looked into this, what struck me wasn’t the size of the theft. It’s that the flaw had been sitting there for five years before anyone noticed.
What Actually Happened
The attack moved funds from 500 separate addresses into one wallet in roughly 25 minutes. That’s not brute force. That’s someone who already knew exactly which private keys to generate, because the wallets that produced them were never as random as they were supposed to be.
Security researchers traced the theft to specific wallets that had generated their seed phrases on Coldcard devices running firmware from a particular window. Once the pattern was public, the scramble began — forums lit up, Coinkite issued advisories, and UK crypto holders who’d never given their hardware wallet a second thought started checking firmware version numbers for the first time.
The Root Cause, in Plain English
Here’s the part that should worry anyone who owns a hardware wallet, not just Coldcard users. The bug wasn’t a hack in the traditional sense — nobody broke in. It was a build error from March 2021, buried in firmware version 4.0.0.
Hardware wallets are supposed to generate private keys using a dedicated hardware random number generator, a chip whose entire job is producing numbers unpredictable enough that nobody — not even someone who knows the exact model of chip — can guess them. Coldcard’s firmware had a build setting that could tell the device to skip that hardware generator entirely.
The failsafe that was meant to catch this only checked whether the setting existed in the code. It never checked whether the setting was actually switched on. So when it was enabled, key generation quietly fell back to a software substitute — seeded using non-secret data like the chip’s serial number and its internal clock registers. Information that, with enough patience, an attacker could work out or guess.
Five years. That’s how long this sat in production firmware before the theft made it visible. UK investors keep asking about this because it undermines a core promise of self-custody — that if you hold your own keys, you’re the only one who can move your coins. This bug meant that, for some users, that was never quite true.
Who’s Affected
Coinkite has confirmed the exposure sits mainly with Coldcard Mk3 devices running firmware 4.0.1 or later. The company initially said its newer Mk4, Q and Mk5 models were unaffected. That assurance didn’t hold for long — researchers at Block later traced a smaller, genuine version of the same underlying flaw into the newer hardware too, though at a much lower risk level than the Mk3 exposure.
If you’re a UK Coldcard owner and your wallet falls into the affected category, updating the firmware does not fix this. The vulnerability lives in how your existing keys were generated, not in code that runs going forward. Coinkite’s guidance, and the guidance echoing across the security community, is blunt: generate an entirely new wallet, with a fresh seed phrase, on unaffected firmware — then move every coin across before anyone else works out your old keys.
How to Check If Your Wallet Is Exposed
Coinkite has published a firmware advisory listing the exact version ranges affected, and it’s worth working through methodically rather than panicking. First, check your device model — Mk3, Mk4, Q or Mk5 — printed on the unit itself or visible in the device menu. Second, check the firmware version your seed was generated under, not just the version currently installed, because the vulnerable build setting affected key generation at creation time, not at every startup.
If your seed was created on an Mk3 running firmware 4.0.1 or later, treat that wallet as compromised until proven otherwise. Mk4, Q and Mk5 owners aren’t entirely in the clear either, given Block’s discovery of a related flaw, so it’s worth waiting for Coinkite’s follow-up guidance before assuming those devices are safe long-term. In the meantime, the safest posture for anyone unsure is the same: generate a new seed on verified-clean firmware, in a private setting, and move funds across before publicising that you’ve done so.
Why This Reignites the Self-Custody Debate
For a decade, the crypto community’s default advice has been “not your keys, not your coins.” Self-custody through a hardware wallet has been sold as the gold standard — safer than leaving funds on an exchange, immune to the counterparty risk that took down FTX and Celsius.
This event doesn’t overturn that logic entirely, but it does complicate it. A hardware wallet is only as trustworthy as its firmware, and firmware is written by people who make mistakes. I’ve seen this pattern with three different exchanges over the years — a “yes it’s secure, trust the code” claim that held up right until a specific build error proved otherwise. The difference here is that Coldcard isn’t an exchange with a support line and insurance reserves. It’s a piece of hardware sitting in a drawer, and the flaw sat undiscovered for years because almost nobody audits firmware build settings line by line.
Some analysts are already framing this as a point in favour of regulated custody and Bitcoin ETFs — vehicles where a licensed institution, not an individual firmware build, is responsible for key security. Whether that’s the right lesson depends on how much you trust an institution versus how much you trust your own diligence. Both, it turns out, can fail.
This Isn’t the First Hardware Wallet Scare
Hardware wallets have had close calls before. Ledger faced backlash in 2023 over a firmware update that technically made key extraction possible under certain conditions, even though the company insisted it would never actually enable the feature without consent. Trezor has had its own physical-access vulnerabilities disclosed by security researchers over the years, patched before wide exploitation. What sets the Coldcard case apart is that this wasn’t a theoretical risk disclosed responsibly — it was actively exploited, at scale, in a single 25-minute window, against a device millions of pounds worth of bitcoin were sitting behind.
Ugly workaround or not, Coinkite’s response has at least been fast by industry standards: advisories went out within a day of the theft being traced, and the company has been transparent about which models are confirmed affected versus still under investigation. That transparency doesn’t undo the losses, but it’s the difference between a company managing a crisis honestly and one trying to make it disappear quietly.
What This Means for UK Readers
If you own a Coldcard, or you’re considering buying one, the practical steps are the same regardless of where you live: check your firmware version against Coinkite’s advisory, and if you’re in the affected window, treat every existing address as compromised. Move funds to a freshly generated wallet built on patched firmware — don’t just apply the update and assume the old keys are now safe, because they aren’t.
For UK investors more broadly, this lands at an awkward moment. The FCA finalised its core rules for the UK’s new crypto licensing regime on 30 June 2026, with firms able to apply for authorisation from September. Part of the pitch behind that regime is that regulated UK crypto firms will have to meet minimum security and operational standards that an individual buying a £150 hardware wallet online never has to meet. A firmware flaw like this one is exactly the kind of incident that argument leans on.
There’s also a less glamorous UK-specific question worth asking: if your coins were stolen through this exploit, does HMRC treat that as an allowable capital loss? In principle, theft can qualify for a negligible value claim in certain circumstances, but the rules are specific and the paperwork burden falls on you. If you’re affected, that’s worth raising with an accountant who understands crypto rather than guessing.
The Uncomfortable Bottom Line
Self-custody still means you’re not relying on an exchange’s solvency or a platform’s uptime. But this incident is a reminder that “not your keys, not your coins” quietly assumes your keys were generated properly in the first place. For 500 wallet holders, that assumption cost them everything in 25 minutes.
Whichever way you store your crypto — hardware wallet, exchange, or a regulated custodian once the FCA regime is live — the lesson from Coldcard isn’t “self-custody is broken.” It’s that security is only as strong as its weakest, least-audited line of code, and that applies whether that code sits on your desk or in someone else’s data centre.
This article is for educational purposes only and does not constitute financial advice. Cryptocurrency investments involve significant risk. Always do your own research.
Stay ahead of the market
Join our community of nearly 5,000 across YouTube, LinkedIn, X, and Facebook — weekly crypto, AI, and digital lifestyle insights every Thursday. No spam. Unsubscribe any time.
Partner picks
Build a smarter digital stack
Explore curated AI, automation, wealth, and creator tools selected for practical value, transparent pricing, and clear use cases.
Disclosure: some links may be affiliate links. DigitechLifestyle may earn a commission at no additional cost to you.



