On the night of July 31, approximately 500 owners of Coldcard hardware wallets fell victim to a theft of 594.48 BTC, valued at around $38.2 million. Analysts from Lookonchain highlighted the incident.

— Lookonchain (@lookonchain) July 31, 2026

The attackers executed the operation in under 30 minutes. Following the theft, all stolen coins were consolidated into a single address and have not yet been moved.

Each compromised wallet contained one signature and held more than 0.15 BTC. Many of these wallets had been inactive for years, with the assets dating back from 2021 to 2026.

Coinkite, the company behind Coldcard, reported on its blog that the vulnerability is linked to the wallet firmware. However, the project representatives did not directly confirm that user accounts had been hacked.

This issue affects all Mk3 firmware versions starting from 4.0.1. It also impacts seed phrases generated on Mk4 and Mk5 devices prior to version 5.6.0, and on Q devices before version 1.5.0Q.

The team has advised hardware wallet owners to update their software as soon as possible. Coinkite is currently conducting an investigation.

It is worth noting that in December 2025, the Trust Wallet browser extension was also targeted by hackers, affecting hundreds of users and resulting in a total loss of $7 million.