Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background
    Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out
    Clarity Act bill with a September 15 calendar and Senate chamber in the background.
    Can the Senate Pass the CLARITY Act on September 15? Here’s the Vote Math
    Simon Gerovich, CEO and President of Metaplanet
    Inside Metaplanet’s Floating Option Pool: How a 2023 Option Clause Followed Its Bitcoin Treasury Era
    Magnifying glass highlighting a red bug icon within broken code, flanked by metallic 3D logos for OpenAI and Anthropic
    OpenAI’s Astra and Anthropic’s Fable 5.1 Put Crypto Security in Focus
    Kevin Warsh, Chair of the Federal Reserve of the United States
    Bitcoin Falls Below $78K as Fed Hike Odds Jump to 56%: What Experts Say
  • Opinion
    OpinionShow More
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    Jackson Hole 2026: Crypto Is No Longer Outside the Fed’s Door
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • Daily Crypto Puzzles
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • IndicesNew
    • India USDT Premium Index
    • India USDC Premium Index
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
    • Daily Crypto Puzzles
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Bitcoin News

Coldcard Hacker Went After Largest Bitcoin Wallets First: Chainalysis

The firm warned affected users that updating firmware alone is not enough and that vulnerable recovery seeds must be replaced.

Written By Iyiola Adrian
Edited by Jahnu Jagtap
Published 2026-08-01·Updated 2 months ago
Make The Crypto Times preferred on GoogleGoogle
Coldcard Hacker Went After Largest Bitcoin Wallets First: Chainalysis

Key Highlights

  • Chainalysis said the Coldcard hacker targeted the largest Bitcoin wallets first, stealing over $38 million from around 500 wallets.
  • The attacker stole about $30 million in the first 10 minutes and completed the wallet sweep in roughly 25 minutes.
  • Coldcard users with affected devices are urged to create a new recovery seed on updated hardware, while Ledger confirmed its wallets were not affected by the vulnerability.

Chainalysis, a blockchain analytics company, said the hacker behind the recent Coldcard wallet attack did not steal Bitcoin at random. Instead, the attacker targeted the largest wallets first, helping steal more than $38 million in Bitcoin. 

In a Friday post on X, Chainalysis shared its findings one day after nearly 594 BTC was stolen from about 500 single-signature Bitcoin wallets linked to vulnerable Coldcard devices. 

Our analysis of the $38M+ Coldcard hack reveals that the attacker hit high-value wallets (including a $1.8M victim) early in the sweep. This pattern suggests that the attacker studied the victim wallet population before proceeding. pic.twitter.com/zpJb0QcCYt

— Chainalysis (@chainalysis) July 31, 2026

Chainalysis details how the attack unfolded 

According to Chainalysis, the attack appears to have been planned before it happened. The hacker likely studied the wallets, identified the ones holding the most Bitcoin, and targeted them first. That strategy allowed the attacker to collect huge amounts of Bitcoin in a very short time. 

Chainalysis said the total value stolen jumped to around $30 million within the first 10 minutes of the attack. In about 25 minutes, the hacker had already swept around 500 different wallets. “Our analysis of the $38M+ Coldcard hack reveals that the attacker hit high-value wallets (including a $1.8M victim) early in the sweep,” the firm stated. “This pattern suggests that the attacker studied the victim wallet population before proceeding.” 

Using its blockchain investigation tool called Reactor, Chainalysis found that three of the ten largest victim wallets each held at least 10 BTC, worth about $636,000 at the time. 

One victim lost around $1.8 million. The company said it is tracking the wallet used by the attacker as well as another address where part of the stolen Bitcoin has been gathered. It also said it is watching for signs that more wallets created with vulnerable Coldcard devices could still be at risk. 

Why a simple software update is not enough 

The company also warned Coldcard users that installing the latest software update alone will not fully protect them if their recovery seed was created using the affected firmware.

“If you own a Coldcard device, applying the latest hotfix is not enough to protect a seed that was generated on vulnerable firmware,” Chainalysis said. “Users must generate an entirely new seed on patched hardware. Utilizing a strong BIP-39 passphrase provides critical additional protection.” 

Coldcard explains the firmware flaw 

The warning came after Canadian hardware wallet maker Coinkite issued an urgent security advisory on July 30. The company said some Coldcard Mk3 devices running firmware versions 4.0.1 through 5.0.3 had a serious problem with the way they generated recovery seeds. Recovery seeds are the secret words that allow users to restore access to their crypto wallets. If those words are not created with enough randomness, they become much easier for attackers to guess. 

Coinkite explained that the issue was caused by a software bug that stopped the device’s hardware random number generator from working as intended during seed creation. Instead of using enough true randomness, the affected devices relied more on software-generated randomness, making some recovery seeds much weaker than they should have been. 

That reduced the number of possible seed combinations and made it possible for a determined attacker to recreate private keys offline and search for wallets holding Bitcoin. The company has released updated firmware that fixes the problem for new recovery seeds created on patched devices.

Ledger says its devices were not affected 

Following the incident, Ledger said its hardware wallets were not affected by the vulnerability. The company said its devices use a certified True Random Number Generator built into the Secure Element chip, allowing every 24-word recovery phrase to be created with the full amount of expected randomness.

Ledger is not affected by the recently published Coldcard Mk3 advisory.

Ledger devices use a certified True Random Number Generator (TRNG) built directly into our Secure Element chip, generating full 256 bits of entropy for every 24-word Secret Recovery Phrase. Please refer to…

— Ledger (@Ledger) July 31, 2026

“Ledger devices use a certified True Random Number Generator (TRNG) built directly into our Secure Element chip, generating full 256 bits of entropy for every 24-word Secret Recovery Phrase,” the company said.

Also Read: WEMIX Hacked Again: $6.25M Stablecoin Exploit Forces Network Shutdown

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

Daily Crypto Puzzles
Tickerdle Tickerdle Crypto Connections Crypto Connections Crypto Crossword Crypto Crossword
TAGGED:BlockchainCrypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Daily Crypto Puzzles

Tickerdle crypto game Tickerdle Crypto Connections game Crypto Connections Crypto Crossword game Crypto Crossword

Latest News

Zenith and DTCC corporate logos displayed side by side.
Zenith Joins DTC Digital Assets Working Group on Tokenization
CLARITY Act document stamped "FAILED" beside a wooden gavel with the U.S. Capitol in the background.
CLARITY Act Fails in Senate as Cloture Vote Falls Short of 60 Votes
CLARITY Act document featuring the U.S. Capitol building resting on a dark wood surface.
TD Cowen Sees 60% Chance Clarity Act Cloture Vote Fails Today
Senator Elizabeth Warren gesturing during a committee hearing.
Warren Calls for Senate No Vote on CLARITY Act Over Trump Ethics
XRP Ledger’s Batch V1.1 Amendment Nears Activation Threshold
XRP Ledger’s Batch V1.1 Amendment Nears Activation Threshold

Find Us on Socials

You may also like

Cracked gold Bitcoin physical coin split in half on dark soil.

Bitcoin Mining Sector Faces Tightest Margins Since the 2024 Halving

A smartphone showing the Arbitrum logo next to an illuminated Standard Chartered wall sign

Standard Chartered Initiates Arbitrum Coverage, Sees ARB Price at $10 by 2030

3D Liquid Network logo with a hooded hacker shadow and computer code overlays in the background

Liquid Network Exploit Explained: Unbacked L-BTC and the $320M Peg-Out

Smartphone displaying the Revolut app logo against a dark background with an illuminated Revolut wall sign behind it.

Revolut Data Breach Hits 680 Customers, UK Opens Probe as Hackers Demand 10,000 Bitcoin

The Crypto Times Logo PNG

News

All News
Market News
Bitcoin News
Ethereum News
Altcoin News
Regulations & Policies
DeFi News
Blockchain News
Industry News

Sections

Exclusive
Opinions
Learn
Insights
Videos
Glossary

India Premium Indices

Stablecoins
USDT
USDC

Play

Daily Crypto Puzzles
Tickerdle
Crypto Connections
Crypto Crossword

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy
Contact Us
Career

Follow Us

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information