New Bitcoin Wallet Attacks Target 448 BTC This August

New Bitcoin Wallet Attacks Target 448 BTC This August

Last updated: August 18, 2026

Quick Answer: A fourth wave of coordinated attacks targeting Coldcard hardware wallets swept approximately 448.7 BTC from around 709 victim addresses in early August 2026, with estimated losses between $28 million and $40 million in this wave alone. The root cause is a firmware flaw in certain Coldcard versions that made wallet seed generation predictable, allowing attackers to reconstruct private keys without phishing or malware. Users who generated seeds on vulnerable firmware must migrate funds immediately to a new, securely generated wallet.

Key Takeaways

  • New Bitcoin wallet attacks target 448 BTC this August, confirmed as the fourth wave of a continuing Coldcard firmware exploit
  • Galaxy Digital’s head of research Alex Thorn identified the suspected fourth attack, describing it as a coordinated “sweep” of pre-identified vulnerable addresses [1]
  • The fourth wave drained funds from roughly 709 addresses in approximately two and a half hours [6]
  • Cumulative losses across all four waves now exceed 2,000 BTC, with total damages estimated at $110 million to over $144 million [5][10]
  • The flaw affects Coldcard Mk2/Mk3 firmware versions 4.0.0 to 4.1.9 and early releases on Mk4, Mk5, and Q devices [4][10]
  • Seeds generated on vulnerable firmware between approximately March 2021 and late-July 2026 emergency patches remain at risk even if the device has since been updated [6][10]
  • Updating firmware alone does not protect existing funds; a new seed must be generated and assets migrated to a fresh wallet [6][10][14]
  • Patched firmware versions are available: 4.2.0 for Mk2/Mk3, 5.6.0 for Mk4/Mk5, and 1.5.0Q for Q devices [4][10]
  • Recovery of stolen funds is considered extremely unlikely given the automated, no-KYC consolidation strategy used by the attacker [4][6]

What Happened With the Bitcoin Wallet Attacks in August

New Bitcoin wallet attacks target 448 BTC this August as the fourth documented wave of exploits against Coldcard hardware wallets struck in early August 2026. Researchers, including Galaxy Digital’s Alex Thorn, confirmed the attack began around August 2 to 3, 2026, systematically sweeping funds from hundreds of addresses linked to wallets with compromised seed generation. [1][4]

What Happened With the Bitcoin Wallet Attacks in August

Key facts from this fourth wave:

  • Addresses affected: approximately 709 suspected victim addresses [1][6]
  • BTC swept: 448.7 to 449 BTC [4][6][9]
  • Estimated value: between $28 million and $40 million, depending on the Bitcoin price at the time of reporting [5][9]
  • Duration: the sweep completed in roughly two and a half hours [6][12]
  • Transaction volume: at least 218 confirmed transactions within a specific block range, with refined counts reaching 709 addresses [4][6]

This was not a random hack. Thorn and other analysts describe the operation as a scripted “drainer” that targeted a pre-compiled list of known vulnerable addresses, consolidating funds into newly created destination wallets with no prior transaction history. [1][4][6]

How Did Hackers Steal 448 BTC: The Technical Method

The attacker did not use phishing, malware, or physical device theft. The exploit works because certain Coldcard firmware versions produced Bitcoin wallet seeds with insufficient randomness, making the seeds mathematically predictable. [10][14][15]

Here is how the attack chain works:

  1. Flawed entropy at seed generation: Coldcard firmware versions released after March 2021 contained a bug in the random number generation used to create wallet seeds. The resulting seeds had a narrower range of possible values than expected.
  2. Key reconstruction: Because the seed space was constrained, an attacker could systematically compute the possible private keys for wallets created on those firmware versions.
  3. Address scanning: The attacker identified Bitcoin addresses corresponding to those reconstructed keys by scanning the blockchain.
  4. Automated sweep: A script then broadcast transactions from each vulnerable address, moving all funds to attacker-controlled wallets before owners could react. [4][6][10]

No user action or mistake was required. The vulnerability was entirely in the device’s software. Coinkite, Coldcard’s manufacturer, has publicly acknowledged the flaw as a software bug rather than user error. [4][6][11]

Which Bitcoin Wallets Were Affected by the August Attacks

The attacks specifically target wallets whose seeds were generated on vulnerable Coldcard firmware. Affected hardware models and firmware ranges include: [4][6][10][14]

DeviceVulnerable Firmware RangePatched Version
Mk2 / Mk34.0.0 to 4.1.94.2.0
Mk4 / Mk5Early releases (post-March 2021)5.6.0
QEarly releases (post-March 2021)1.5.0Q
Edge (X/QX)Early releases6.6.0X/QX

Any seed created on these firmware versions between approximately March 2021 and the late-July 2026 emergency patches should be treated as compromised, regardless of whether the device firmware has since been updated. [6][10][14]

Wallets from other manufacturers (Ledger, Trezor, BitBox, etc.) are not directly affected by this specific vulnerability, as it is unique to Coldcard’s flawed entropy implementation.

Did Coinbase or Kraken Get Hacked in August

No. Coinbase, Kraken, and other centralized exchanges were not hacked in this incident. The August 2026 attacks exclusively targeted self-custody Bitcoin wallets created on vulnerable Coldcard hardware wallet firmware. [4][6][10]

Users who hold Bitcoin on exchange accounts or in wallets generated by other hardware or software products are not affected by this specific exploit. The attack vector requires that the victim’s private key was derived from a seed generated by the flawed Coldcard firmware.

What Type of Attack Was Used on Bitcoin Wallets

This is a deterministic key-reconstruction attack, also called a weak-entropy or seed-prediction exploit. It differs from the most common crypto theft methods in a significant way: the attacker never needed access to the victim’s device, password, or personal data. [10][14][15]

Common attack types compared:

  • Phishing: Tricks users into revealing seed phrases. Not used here.
  • Malware: Intercepts clipboard data or keystrokes. Not used here.
  • Physical theft: Steals the hardware device. Not used here.
  • Weak-entropy exploit (this attack): Reconstructs private keys mathematically from a predictable seed space. Used here.

The operational speed was striking. An earlier wave drained roughly $38 million in approximately 25 minutes. [8] The fourth wave swept nearly 449 BTC across hundreds of addresses in about two and a half hours, at a sweep rate estimated at around 45 times the normal baseline transaction activity for those addresses. [6][12]

Is My Bitcoin Wallet Safe From These Attacks

Your wallet is safe if it was not generated on vulnerable Coldcard firmware. Specifically, you are not at risk if any of the following apply: [4][6][10]

  • Your wallet was created using a different hardware wallet brand
  • Your Coldcard wallet seed was generated on patched firmware (4.2.0+ for Mk2/Mk3, 5.6.0+ for Mk4/Mk5, 1.5.0Q+ for Q)
  • You already migrated funds to a new wallet generated on patched firmware

You are at risk if your seed was generated on a Coldcard running firmware 4.0.0 through 4.1.9 (Mk2/Mk3) or an equivalent early release on Mk4, Mk5, or Q, and you have not yet moved your funds.

“Simply updating the firmware on your existing Coldcard device does not protect funds in a wallet whose seed was already generated by the vulnerable code. The seed itself is compromised.” [6][10][14]

How Can I Protect My Bitcoin Wallet From These Attacks

The single most important action for affected users is to move funds immediately. Updating the firmware is necessary but not sufficient. [6][10][14]

Step-by-step migration guide:

  1. Check your Coldcard firmware version against the vulnerable ranges listed above.
  2. Update to patched firmware on your device (4.2.0 for Mk2/Mk3, 5.6.0 for Mk4/Mk5, 1.5.0Q for Q).
  3. Generate a completely new seed on the patched firmware. Do not reuse the old seed.
  4. Write down the new seed phrase securely, offline, and store it in a physically safe location.
  5. Send all funds from the old wallet to the new wallet address, using a higher-than-average transaction fee to reduce the risk of being front-run by the attacker’s automated sweep script. [1][4][6]
  6. Verify the transfer is confirmed on the blockchain before considering the migration complete.
  7. Do not reuse the old wallet addresses for any future transactions.
How Can I Protect My Bitcoin Wallet From These Attacks

What’s the Difference Between Hot and Cold Wallet Security

A hot wallet is connected to the internet (mobile apps, browser extensions, exchange accounts). A cold wallet, like Coldcard, stores private keys offline on a physical device. Cold storage is generally considered more secure because it is not exposed to online attacks. [10][11]

However, the August 2026 Coldcard attacks demonstrate that cold wallets are not immune to all threats. A flaw in the key generation process can make a cold wallet just as vulnerable as a poorly secured hot wallet, because the weakness exists in the seed itself rather than in the device’s online exposure.

Key distinction for this incident: The attack did not exploit the “cold” nature of the wallet. It exploited the mathematical weakness of the seed, which would have been equally vulnerable whether the wallet was used online or offline.

Why Are Bitcoin Wallets Being Targeted Right Now

The timing of these attacks is driven by the discovery and exploitation of a known, finite pool of vulnerable addresses. As long as significant Bitcoin value remains in wallets generated on vulnerable Coldcard firmware, attackers have a financial incentive to continue sweeping them. [4][6][10]

The cumulative scale of losses explains the urgency:

  • Wave 1 to 3 combined: approximately 1,367 BTC from 4,585 addresses, later revised upward to around 1,596 BTC [5][7][10]
  • After Wave 4: total losses exceed 2,000 BTC, with estimates ranging from $110 million to over $144 million depending on the Bitcoin price used [5][10]
  • This incident is now described by industry analysts as the largest hardware wallet hack of 2026 [5][11][14]

Analysts expect further sweeps to continue as long as unprotected funds remain in vulnerable addresses. [4][6][10]

Can Stolen Bitcoin Be Recovered or Traced

Tracing is possible; recovery is extremely unlikely. Blockchain transactions are publicly visible, so researchers can follow the movement of stolen funds on-chain. However, the attacker is consolidating funds into newly created addresses with no KYC (know-your-customer) history, making it very difficult to link the destination addresses to a real-world identity. [4][6][10][14]

Forensic and blockchain analytics firms can flag and monitor the stolen funds. If the attacker attempts to cash out through a regulated exchange, there is a small chance of identification and asset freezing. But given the automated, privacy-conscious consolidation strategy observed, successful recovery for individual victims is considered extremely limited. [4][6][10][14][15]

How Do I Know If My Bitcoin Was Stolen

Check your wallet balance directly on a blockchain explorer such as mempool.space or blockstream.info by entering your Bitcoin address. If the balance shows zero and there are recent outgoing transactions you did not authorize, your funds have likely been swept. [4][6]

Signs your wallet may have been compromised:

  • Unexpected zero balance on a previously funded address
  • Recent outgoing transactions to an unfamiliar address with no prior history
  • Your Coldcard firmware version falls within the vulnerable range and you have not yet migrated

If you confirm unauthorized transactions, document the transaction IDs and destination addresses. Report the incident to Coinkite and consider filing a report with relevant financial crime authorities in your jurisdiction, though recovery prospects remain low. [4][6][10]

What Are Common Bitcoin Wallet Vulnerabilities

Beyond the Coldcard entropy flaw, Bitcoin wallet security can fail at several points:

  • Weak seed generation: Insufficient randomness during wallet creation (the core issue in this attack)
  • Seed phrase exposure: Writing down seed phrases in insecure locations or storing them digitally
  • Phishing attacks: Fake wallet apps or websites that capture seed phrases during entry
  • Supply chain attacks: Tampered hardware devices shipped with pre-compromised firmware
  • Clipboard hijacking: Malware that replaces copied Bitcoin addresses with attacker-controlled ones
  • Social engineering: Scammers posing as support staff to extract seed phrases

The Coldcard incident is unusual because it required no user error at all. Most other attack vectors depend on the user making a mistake. [10][11][14][15]

How Do I Move My Bitcoin to a Safer Wallet

Moving Bitcoin to a safer wallet requires generating a new seed on secure, audited hardware or software and then sending funds from the old address to the new one. For Coldcard users specifically, the process is outlined in the protection steps above.

For users considering a broader wallet change:

  • Hardware wallets with clean audit records (Ledger, Trezor, BitBox02) remain strong options for cold storage, provided firmware is kept updated
  • Multi-signature wallets distribute signing authority across multiple devices, so a single compromised key cannot drain funds
  • Air-gapped signing devices that never connect to any network reduce online attack surfaces
  • Software wallets (Sparrow, Electrum) are acceptable for smaller amounts but require a secure, malware-free computer

Always verify the wallet software or firmware download against the official developer’s published cryptographic signature before installing. [6][10][14]

Conclusion

The new Bitcoin wallet attacks targeting 448 BTC this August are not an abstract threat. They represent a concrete, ongoing drain of real funds from thousands of real users, driven by a deterministic flaw in Coldcard’s seed generation code. Cumulative losses now exceed 2,000 BTC and $110 million across four documented waves. [5][10]

Actionable next steps for Coldcard users:

  1. Check your firmware version immediately against the vulnerable ranges.
  2. Update to patched firmware and generate a brand-new seed.
  3. Migrate all funds from old wallets to the new wallet using a competitive transaction fee.
  4. Confirm the migration on-chain before decommissioning the old wallet.
  5. Store the new seed phrase offline, physically secured, and never digitally.

For all Bitcoin holders, this incident reinforces that hardware wallet security depends entirely on the integrity of the key generation process, not just the physical security of the device. Independent firmware audits, transparent entropy sourcing, and prompt patching are now baseline expectations, not optional extras.

FAQ

What is the Coldcard Bitcoin wallet vulnerability? Certain Coldcard firmware versions released after March 2021 contained a flaw in random number generation during seed creation, producing wallet seeds that were mathematically predictable and therefore reconstructable by an attacker. [10][14]

How much Bitcoin was stolen in the August 2026 Coldcard attacks? The fourth wave alone swept approximately 448.7 to 449 BTC, worth between $28 million and $40 million. Cumulative losses across all four waves exceed 2,000 BTC and an estimated $110 million to $144 million. [5][9][10]

Who identified the fourth Coldcard attack wave? Alex Thorn, head of research at Galaxy Digital, publicly identified and described the suspected fourth Coldcard attack wave involving 448 BTC in early August 2026. [1][2]

Does updating my Coldcard firmware protect my existing funds? No. Updating the firmware secures future seed generation but does not fix a seed that was already created with the vulnerable code. You must generate a new seed on patched firmware and migrate your funds. [6][10][14]

Which Coldcard firmware versions are safe to use? Safe versions are 4.2.0 or later for Mk2/Mk3, 5.6.0 or later for Mk4/Mk5, 1.5.0Q or later for Q devices, and 6.6.0X/QX or later for Edge releases. [4][10]

Were any exchanges hacked in the August 2026 Bitcoin attacks? No. Coinbase, Kraken, and other centralized exchanges were not involved. The attacks exclusively targeted self-custody wallets generated on vulnerable Coldcard firmware. [4][6]

How fast did the attackers drain the wallets? The fourth wave swept nearly 449 BTC from hundreds of addresses in approximately two and a half hours. An earlier wave drained roughly $38 million in about 25 minutes. [6][8][12]

Can I recover my stolen Bitcoin? Recovery is extremely unlikely. The attacker consolidates funds into new, no-KYC addresses using automated scripts. Blockchain tracing is possible, but converting that into asset recovery requires identifying the attacker, which has not occurred as of mid-August 2026. [4][6][10]

Is this the largest hardware wallet hack ever? Industry analysts describe the Coldcard exploit as the largest hardware wallet hack of 2026, with total damages framed as a $110 million to $144 million-plus event. [5][11][14]

What should I do if I think my wallet was compromised? Check your wallet balance on a blockchain explorer. If you find unauthorized outgoing transactions, document the transaction IDs, report to Coinkite, and file a report with relevant financial crime authorities. Do not send additional funds to the compromised address. [4][6][10]

References

[1] Galaxys Thorn Identifies Suspected Fourth Coldcard Attack Involving 448 Btc Crypto Scams Crypto Hacks 11858671 – https://www.gadgets360.com/cryptocurrency/news/galaxys-thorn-identifies-suspected-fourth-coldcard-attack-involving-448-btc-crypto-scams-crypto-hacks-11858671

[2] Galaxys Thorn Identifies Suspected Fourth Coldcard Attack Involving 448 Btc Crypto Scams Crypto Hacks News 11858671 – https://turbo.gadgets360.com/en/cryptocurrency/galaxys-thorn-identifies-suspected-fourth-coldcard-attack-involving-448-btc-crypto-scams-crypto-hacks-news-11858671

[3] Researchers Warn Of New Bitcoin Wallet Attacks As 448 Btc Is Swept From Hundreds Of Addresses News 11862713 – https://www.gadgets360.fr/internet/researchers-warn-of-new-bitcoin-wallet-attacks-as-448-btc-is-swept-from-hundreds-of-addresses-news-11862713

[4] Coldcard Losses Rise As Fourth Attack Wave Sweeps 448 Btc – https://crypto.news/coldcard-losses-rise-as-fourth-attack-wave-sweeps-448-btc/

[5] Bitcoin Wallet Bug Sparks 144m Crypto Heist – https://ia.acs.org.au/article/2026/bitcoin-wallet-bug-sparks–144m-crypto-heist.html

[6] Coldcard Wallet Attacks Enter Fourth Wave Putting 449 Btc At Risk – https://cryptopotato.com/coldcard-wallet-attacks-enter-fourth-wave-putting-449-btc-at-risk/

[7] Bitcoin Cold Wallet Attack Spreads To 4 500 Addresses As Losses Near Usd89 Million – https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million

[8] Bitcoin Wallet Exploit Costs Users Usd 38 Million In 25 Minute Attack Crypto Frauds Attacks Scams News 11848983 – https://turbo.gadgets360.com/en/cryptocurrency/bitcoin-wallet-exploit-costs-users-usd-38-million-in-25-minute-attack-crypto-frauds-attacks-scams-news-11848983

[9] Bitcoin The Loss Counter Wont Stop After The Coldcard Hack – https://www.cointribune.com/en/bitcoin-the-loss-counter-wont-stop-after-the-coldcard-hack/

[10] Coldcard Wallet Losses 114 Million Fourth Attack Wave – https://genfinity.io/2026/08/04/coldcard-wallet-losses-114-million-fourth-attack-wave/