**$1.6 Million Drained in a Blink: A Deep Dive into the Recent Coldcard Wallet Hack**
A Canadian entrepreneur, Jonathan Goodman, lost a staggering **18.25 BTC (over $1.6 million)** in less than seven minutes in late July 2026. The shocking theft targeted his Coldcard hardware wallet, a device specifically designed for “cold storage”—keeping private keys completely offline. The incident has sent ripples through the crypto community, exposing a critical vulnerability that challenges the very foundation of self-custody security.
### How One Holder Lost 18 BTC in Seven Minutes
Goodman’s story is particularly unsettling because he followed best practices meticulously. He stored his Coldcard device in a safety deposit box, ensuring it was never connected to the internet. His funds were spread across multiple safes, protected by a seed phrase he never shared. He believed he had done everything right.
**However, between 9:36 and 9:43 PM on July 29, 2026, every wallet he controlled was systematically emptied.**
The problem did not originate from his physical security measures. Instead, it traced back to a fundamental flaw in the seed generation process.
### What Galaxy Research Found in the Attack Data
The scale of the breach is massive. According to research from Galaxy Research, the attacks appear to be part of a coordinated wave that has already drained **1,367.05 BTC (worth roughly $88.6 million at the time)** across **4,585 different addresses**.
The investigation points to a vulnerability that dates back to 2021. A flaw in the code responsible for generating seed phrases left certain Coldcard devices exposed. Attackers allegedly leveraged artificial intelligence to brute-force these weakened seed phrases, granting them access to the supposedly secure wallets.
Goodman first became aware of a broader issue while at his cottage. Assuming he might be unaffected, he checked his Wasabi wallet and was horrified to see a series of red withdrawal transactions. He is now filing reports with the police and the Ontario Securities Commission, though he acknowledges that recovery hopes remain slim.
**Key Findings:**
– The attacks show patterns suggesting a common operator, with two initial waves followed by a distinct third wave, indicating possible updated tools or new actors.
– The stolen Bitcoin remains dormant in attacker-controlled addresses, having sat untouched for an average of 3.18 years. This suggests the targets were primarily long-term holders, not active traders.
– Galaxy Research emphasizes that their findings are based on on-chain data and have not definitively confirmed the root cause as insufficient randomness in address generation.
### FAQ
**Q: How is this possible? My hardware wallet is supposed to be secure.**
A: Hardware wallets like the Coldcard are secure, but they rely on an initial seed phrase generated by the device. A vulnerability in the code used to create this phrase can produce seeds that are weak or predictable, allowing attackers to potentially guess them, even if the device has never been online.
**Q: What should I do if I own a Coldcard wallet?**
A: If you have not moved funds from a Coldcard wallet generated with the default seed-generation method, it is urgent that you do so immediately. You should also upgrade your device’s firmware to the latest version, which patches the identified vulnerability.
**Q: Can I recover my stolen Bitcoin?**
A: Unfortunately, recovery is highly unlikely. The Bitcoin stolen in this hack remains in attacker-controlled wallets with no further movement, suggesting it may be held indefinitely or moved through mixing services, making tracing and retrieval impossible.
**Q: Does this mean self-custody is unsafe?**
A: While this event is a stark reminder that “doing everything right” may not always be enough, it does not mean self-custody is inherently flawed. The incident highlights the importance of understanding the specific tools you use. Relying solely on default settings can sometimes expose you to hidden risks. Using additional, manual entropy sources, such as dice rolls, is a recommended alternative.
### Conclusion
The Coldcard wallet hack serves as a sobering wake-up call for the entire cryptocurrency community. It demonstrates that even the most diligent security practices can be undermined by a flaw deep within the technology itself. As Alex Thorn of Galaxy Research noted, this is “a blow to bitcoin self-custody” that forces us to critically examine the tools we trust and the assumptions we make about security. Users must now navigate a landscape where verifying hardware integrity requires not just physical safety, but a deeper understanding of the invisible digital seeds that guard their assets.



