The Coldcard $89M Exploit Timeline: What Happened in the 3 Waves of Drains
A detailed chronological post-mortem of the $89 Million (1,367 BTC) Coldcard vulnerability exploit across 4,585 addresses and 3 distinct drain waves in August 2026.
Overview of the $89M Coldcard Vulnerability Escalation
Between July 30 and August 3, 2026, the Coldcard Random Number Generator (RNG) flaw escalated into one of the largest single hardware wallet security crises in Bitcoin's history.
On-chain analysis confirmed by security research teams at Galaxy Digital and CoinDesk established that total stolen funds reached approximately $89 Million USD (~1,367 BTC across 4,585 distinct Bitcoin addresses).
The catastrophic loss was enabled by offline brute-forcing of weak seed phrase derivation paths. Because the build header bug (MICROPY_HW_ENABLE_RNG (0)) disabled hardware TRNG peripherals across affected devices, seed generation degraded silently to the software Yasmarang PRNG. Attackers were able to precompute elliptic curve keypairs offline, match them against public blockchain balances, and systematically sweep funds without triggering any initial warning on affected devices.
The 3 Distinct Waves of Address Drains (July 30 – August 1, 2026)
Detailed transaction analysis reveals that the attacker operated with high technical discipline, executing the theft across three distinct, automated waves:
Wave 1: High-Value Whales (July 30, 2026)
- Scope: 1,082 high-value Bitcoin addresses.
- Stolen Funds: 1,082.00 BTC (~$70.3M USD).
- Strategy: The initial wave prioritized key combinations derived from narrow millisecond windows on early Mk3 and Mk4 setups holding large balances. The attacker swept these addresses first to maximize total yield before public advisories were published.
Wave 2: Mid-Tier Wallet Sweep (July 31, 2026)
- Scope: 1,478 smaller wallet addresses.
- Stolen Funds: 76.16 BTC (~$4.9M USD).
- Strategy: As news of the flaw began spreading through social media and developer channels, the attacker launched an automated secondary sweep script targeting mid-value wallets across secondary release tracks.
Wave 3: Automated Residual Sweep (July 31 – August 1, 2026)
- Scope: 1,912 addresses.
- Stolen Funds: 208.24 BTC (~$13.5M USD).
- Strategy: The final wave executed a broad sweep across residual addresses holding smaller balances, effectively draining virtually every unpassphrased wallet generated on vulnerable firmware tracks.
Attacker Discipline and On-Chain Tracking
A defining characteristic of the Coldcard exploit was the attacker's operational discipline on-chain:
- Offline Precomputation: The attacker did not probe addresses or interact with the Bitcoin network prior to broadcasting the sweeping transactions. All 4,585 keypairs were generated in memory using offline cracking rigs.
- UTXO Consolidation: Stolen funds were consolidated into thousands of unspent output addresses controlled by the attacker.
- No Immediate Exchange Ingress: As of August 3, 2026, the attacker has not attempted to move funds onto centralized exchanges, coin mixers, or cross-chain bridges, likely anticipating immediate OFAC tagging and chain-analysis flagging.
For Bitcoin holders, this event underscores that blockchain visibility is transparent after the fact, but offers zero protection against offline private key derivation.
Key Takeaways for Self-Custody and Key-Person Contingency
The $89M Coldcard exploit highlights fundamental vulnerabilities in single-device self-custody models:
- Vendor Single Point of Failure: Trusting a single hardware manufacturer's build pipeline creates systemic risk. Multi-vendor multisig setups remain the highest defense standard.
- Emergency Response Velocity: When a supply chain flaw hits, users must be able to rotate keys immediately.
- Automated Handoff Protocol: If a key-holder is unreachable or incapacitated during an ongoing exploit, designated backup operators or family members must have access to emergency runbooks and contingency instructions.
Services like ZeroLatch provide a client-side encrypted dead man's switch with a 1-day minimum check-in interval, ensuring your backup runbooks and vault notes reach trusted recipients if you are unable to respond during a security emergency.
ZeroLatch Editorial Team
We publish practical guidance about secure future delivery, digital continuity, and the decisions families and small businesses should discuss before an emergency. Review our security model.
Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute legal, financial, or technical advice. ZeroLatch is a software service, not a law firm. We recommend consulting with qualified professionals regarding your specific estate planning, data privacy, and security needs.
Leave instructions, not wallet seeds
Prepare a separate encrypted delivery with the inventory, contacts, and recovery sequence your chosen person will need.
Prepare a crypto continuity delivery →Every plan includes a 14-day free trial. View pricing.