What Has Been Reported About the Coldcard Wallet Hack
Coinkite said on August 4 that it had been under attack since the prior Friday and would cover the incident fully in a forthcoming post-mortem, according to a statement on its blog. The company said it could not identify which units or addresses were involved from its side. For related coverage, see Ethics Deal May Force Trump to Sell Crypto Holdings.
The reported financial impact comes from outside parties, not Coinkite. Hackers stole over $130 million by exploiting a bug in the offline wallets, TechCrunch reported on August 4, citing researchers including Galaxy Research and Elliptic. For related coverage, see Putin Signs Russia's First Crypto Law: Trading Legal, Payments Banned.
That figure remains a researcher estimate, according to unconfirmed reporting, and Coinkite has said it cannot estimate losses from its own vantage point. Prior coverage tracked the tally as it climbed, with early accounts placing losses above $100 million before the wider $130 million estimate surfaced.
The distinction matters for COLDCARD owners because the flaw is narrow. Coinkite’s advisory says the issue affects seeds generated on-device immediately after reset on COLDCARD Mk2, Mk3, and Q1 devices, while seeds mixed with 50 or more private dice rolls are not affected, per the company’s seed-generation warning.
Why Coinkite Is Preparing a Post-Mortem
A post-mortem is a formal accounting of a security incident: what happened, the root cause, the scope of impact, and the steps taken to prevent a repeat. Coinkite has committed to documenting the event fully rather than releasing piecemeal detail while the attack is, from its perspective, still active.
The technical root cause has already been outlined externally. Block’s engineering team said the bug involved a predictable RNG fallback caused by symbol resolution between libngu and MicroPython, combined with a 32-bit reseed issue in older firmware behavior, in a detailed analysis. That flaw made some generated seeds predictable, and therefore guessable by an attacker.
Coinkite’s immediate communication priority has been user safety, not attribution. The company warned affected users not to expose wallet details publicly or trust unsolicited helpers replying to their posts, a caution aimed at limiting secondary theft from opportunists.
Independent reporting has already tied the losses to a years-old firmware flaw, underscoring why a company-authored timeline carries weight: it can confirm when the vulnerability was introduced, when it was fixed, and which firmware versions remain exposed.
What the Incident Means for Hardware Wallet Security
For users, the practical takeaway is version-specific. Owners of Mk2, Mk3, and Q1 devices who generated a seed on-device right after a reset, without adding dice-roll entropy, fall inside the affected boundary and should treat their funds as potentially at risk. Those who mixed in 50 or more dice rolls sit outside it.
The market response has so far separated wallet-trust concerns from broad price panic. Bitcoin traded at $64,243 in the supplied snapshot, down 0.53% over 24 hours, indicating limited immediate price contagion from the exploit headlines.
Sentiment, however, was already cautious. The crypto Fear and Greed Index read 29, or Fear, a risk-sensitive backdrop even as coverage focused more on self-custody confidence than on selling Bitcoin outright.
The episode is also feeding a structural debate. CoinDesk reported on August 5 that analysts believe the exploit could shift some demand toward regulated Bitcoin exposure instead of direct self-custody, as a potential tailwind for those products. That framing echoes wider questions about custody choices raised in debates over corporate Bitcoin ETF exposure versus holding coins directly.
As of August 7, Coinkite has not published the promised full post-mortem, nor a company-confirmed final loss total, victim count, or definitive affected-wallet list. Those gaps are precisely what its report is expected to close, which is why the document will be the reference point for gauging the true scope of the incident.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.