On the night of July 31, a major incident occurred in the cryptocurrency space involving Coldcard hardware wallets. Attackers managed to steal 594.48 BTC, which amounts to approximately $38.2 million. The attack targeted around 500 users owning devices of this brand.

Lightning-Fast Attack and Vulnerable Software

Analysts from the Lookonchain service were the first to notice anomalous activity on the network. Hackers demonstrated high efficiency: the entire operation to move funds took less than 30 minutes. After the theft, all stolen coins were centralized on a single address (bc1qnk) and have not been moved since.

A detailed analysis of the affected accounts showed that each contained more than 0.15 BTC and had only one signature. A significant portion of the assets had been dormant for years, with the age of the bitcoins ranging from 2021 to 2026.

The device manufacturer, Coinkite, confirmed in its blog the existence of a vulnerability in the wallet firmware. However, project representatives have not yet directly confirmed the fact of specific user hacks, focusing instead on the technical side of the issue.

Scale of the Problem and Recommendations

The vulnerability turned out to be systemic and affects a wide range of device versions. The issue was found in all firmware versions of the Mk3 model, starting from version 4.0.1. Furthermore, the risk extends to seed phrases generated on Mk4 and Mk5 models prior to version 5.6.0, as well as Q devices prior to version 1.5.0Q.

The Coinkite team strongly recommended that all owners of hardware devices update their software as soon as possible to prevent similar incidents from recurring. Currently, the company is conducting an internal investigation into the circumstances of the fund leak.

Context of Cryptocurrency Security

This incident fits into a series of major attacks on crypto infrastructure recorded recently. In December 2025, the Trust Wallet browser extension fell victim to hackers, with damages totaling $7 million. Blockaid analysts called the first half of the year a record for the number and scale of cryptocurrency hacks, highlighting the need for constant attention to the security of digital assets.