Community Trust ScoreVerified
Jonathan Goodman did everything right. The Canadian entrepreneur kept his Coldcard hardware wallet locked in a safety deposit box, never touched the internet with it, followed every best-practice guideline he could find. And on July 29, 2026, he still lost 18.25 BTC — roughly $1.6 million — in seven minutes flat.
He only found out because he happened to check his balances through Wasabi wallet software. The withdrawals were already done. Gone. Goodman says he had no idea there were vulnerabilities affecting Coldcard devices at all, which is kind of the worst part of it. You can’t defend against a threat you don’t know exists. He’s since filed reports with the police and the Ontario Securities Commission, but he’s pretty much acknowledged the odds of recovering anything are slim.
The theft wasn’t random bad luck.
A Seed Flaw Baked In Since 2021
The problem traces back to a flaw in Coldcard’s seed phrase generation code — and that flaw has apparently been sitting there since 2021. Attackers allegedly used artificial intelligence to brute-force seed phrases on wallets created with insufficient randomness, meaning devices that generated seeds using Coldcard’s default method were potentially wide open to anyone with the right tools and enough compute power.
Galaxy Research has now mapped out three distinct waves of attacks hitting Coldcard addresses. Across those waves, 4,585 source addresses were drained. Total losses: approximately 1,367.05 BTC, valued at around $88.6 million. That’s not a rounding error. That’s a serious, coordinated theft campaign running across what looks like months of activity.
Alex Thorn from Galaxy Research noted that the compromised wallets had been dormant for an average of 3.18 years before they were hit. Long-term holders. People who set up their wallets years ago and trusted the hardware to keep doing its job quietly. They weren’t watching closely, and that’s probably exactly what the attackers were counting on.
The three waves aren’t identical, either. The first two shared transaction patterns — similar enough that Galaxy Research thinks they might point to a single operator. The third wave looked different, which either means upgraded tools or a completely separate actor who caught wind of the vulnerability and decided to run their own campaign. Unclear which. Galaxy Research says its conclusions are based on on-chain data, and the exact mechanism behind the insufficient randomness hasn’t been definitively confirmed yet.
What’s striking is where the stolen Bitcoin is now. It’s sitting still. The hacker-controlled addresses haven’t moved the funds, which is unusual and doesn’t make the victims feel any better about their chances of recovery.
Coldcard’s “Low Risk” Label Now Under Fire
Here’s where it gets uncomfortable for Coldcard. The company’s own documentation describes its default seed-generation method as “low risk.” That’s the exact method Galaxy Research links to the losses. Coldcard’s marketing slogan — “Don’t Trust, Verify” — reads pretty differently now that devices with entropy flaws apparently ran for years without anyone catching it.
To be fair, Coldcard’s manual does mention alternatives. Users can combine hardware output with dice rolls, which the company suggests as a way to reduce reliance on the device itself. But most users went with the default. Why wouldn’t they? The documentation called it low risk. The hardware was supposed to handle it.
The tension here is real and it’s not simple. Coldcard has to maintain reproducibility so users can verify firmware — that’s a legitimate security concern in its own right. But that same design philosophy apparently created a window for seed generation to be weaker than it should be. It’s a fundamental tradeoff in self-custody hardware, and right now it’s costing people millions.
Goodman’s case is the most visible, but he’s far from alone. The 4,585 affected addresses span multiple users, multiple wallets, multiple years of dormant holdings. And the attacks are apparently still ongoing, per Galaxy Research, which is urging anyone with a potentially vulnerable wallet to move funds immediately.
What Affected Users Should Do Now
The advice from Galaxy Research and the broader community is pretty consistent: check your setup, assess whether your wallet was generated using the default method, and migrate funds if there’s any doubt. Generate new seeds. Update devices. Don’t wait.
Coldcard users who relied on the default seed-generation process — especially those who set up wallets between 2021 and whenever the flaw was addressed — are being told to treat their current wallets as potentially compromised until proven otherwise. That’s a harsh position to be in, especially for long-term holders who built their whole security strategy around hardware wallets precisely because they seemed like the safest option.
The self-custody community is having a hard conversation right now about what “secure” actually means. Hardware wallets were supposed to be the answer. Air-gapped, offline, physically secured — Goodman had all of that and still lost $1.6 million in seven minutes.
Galaxy Research puts the total confirmed theft at 1,367.05 BTC across 4,585 addresses, with stolen funds still sitting untouched in attacker-controlled wallets.
Frequently Asked Questions
How much Bitcoin was stolen in the Coldcard wallet attacks identified by Galaxy Research?
Galaxy Research identified approximately 1,367.05 BTC stolen across 4,585 source addresses, valued at roughly $88.6 million at the time of the attacks.
What caused the Coldcard wallet vulnerability?
A flaw in Coldcard’s seed phrase generation code dating to 2021 created insufficient randomness in affected wallets, which attackers allegedly exploited using artificial intelligence to brute-force seed phrases.




