The timeline provided outlines a significant security breach involving Coldcard hardware wallets, leading to the theft of approximately 85 million USD worth of Bitcoin. Here are the key events:
-
July 29, 2026: Coinkite acknowledges an issue with firmware affecting Coldcard MK3 devices.
-
July 30, 2026:
- A security researcher reports that a hacker is draining funds from Coldcard wallets.
- The attacker uses the compromised seed phrases to steal Bitcoin.
- Coinkite initially underestimates the extent of the breach.
-
July 31, 2026:
- Coinkite admits that firmware issues affect multiple Coldcard models (MK3, MK4, MK5, and Q).
- The compromised seed phrases have reduced entropy.
- Block Engineering identifies suspicious activity from an attacker using a blockchain data provider's logs.
-
August 1, 2026:
- Security researchers confirm that newer Coldcard models are also being drained.
- Galaxy Research estimates the total loss exceeds 1,367 BTC from over 4,585 addresses.
Read the full article at Protos
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





