Coldcard exploit highlights private keys as crypto’s Achilles’ heel, with ~75% of H1 2026 losses from private-key compromises and over $1B in total exploit losses, including ~$130M stolen and 7,000 addresses affected.
Coldcard firmware flaw enabled a $70M theft (1,196 BTC) in 41 minutes, traced to a March 2021 integration error that routed seed generation to a deterministic PRNG.
Galaxy Research estimates up to 2,055 BTC (~$130M) stolen from Coldcard seed vulnerabilities across three confirmed waves, with a potential fourth wave; regulatory cooperation with U.S. authorities adds an enforcement angle.
Coinkite warns Coldcard Mk3 users of risk amid 594 BTC theft reports and urges a strong BIP-39 passphrase plus moving funds to the derived wallet.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.