BLOCKCHAIN AI.NEWS

Security · Analysis

The Vault Got Robbed: What the $116M Coldcard Exploit Says About Everyone's Cold Storage

Attackers didn't steal a single device. A 2021 firmware flaw weakened seed generation enough to brute-force keys from anywhere — and the industry's "buy a hardware wallet, you're done" advice is the real casualty.

Editorial illustration: an open vault door with a stream of coins siphoning away into the dark
✓ First reported by Bloomberg (Aug 3) · Technical analysis: TRM Labs · Additional reporting: TechCrunch, Fortune

Beginning July 30, attackers drained roughly 1,816 BTC — about $116 million — from more than 5,200 addresses associated with Coldcard hardware wallets, according to TRM Labs' technical analysis. Bloomberg first reported the ongoing attack on August 3.

The mechanism matters more than the number. Per TRM, a firmware bug introduced in March 2021 weakened the randomness used when some devices generated their wallet seeds, cutting effective key strength from 128 bits to as little as 40. At 40 bits, keys fall to brute force — no physical access, no phishing, no user error required. The wallets did exactly what their owners asked; the math underneath had quietly failed years earlier.

Why this one stung

Hardware wallets occupy a special place in crypto's security story: they are the thing you buy so you can stop worrying. As Fortune observed, this exploit hurt more than a typical bridge hack precisely because it hit the people doing everything "right." TRM ranks it the third-largest crypto theft of 2026, in a year already past $1.2 billion across 276 incidents.

The compounding problem: doxxed owners

The same month, SafePal disclosed a breach exposing order records — names, home addresses, contact details — for 39,798 hardware-wallet customers. No funds were touched; none needed to be. A verified list of cold-storage owners, with home addresses, is raw material for targeted phishing at minimum.

And the tempo is rising

TRM reports AI adoption across crypto crime up roughly 40% year over year, and industry leaders warned in The Block that autonomous agents could make current loss figures "look like pennies." The Coldcard brute-forcing — patient, automated, aimed at everyone with a weak seed simultaneously — is what that future looks like at small scale.

The Take

The wrong lesson is "hardware wallets failed." Cold storage remains the right architecture. The right lesson is that the device was never the security — the habits are. Three practical ones: know when and on what firmware your seed was generated, and migrate if it falls in a disclosed flaw window; read vendor advisories the way pilots read airworthiness directives; and treat concentration as a choice — one seed guarding everything means one bad firmware week costs everything.

More on the subject