Hardware wallets were supposed to be the safe answer. Air-gapped, offline, immune to the hacks that plague exchanges. Then July 30, 2026 happened, and about 1,196 Bitcoin wallets found out the hard way that “offline” and “safe” are not the same word.

A firmware flaw buried inside Coldcard Mk3 devices since March 2021 allowed attackers to drain approximately 1,082.65 BTC, worth roughly $70 million at the time of the attack, in a window spanning just 41 minutes between 1:10 and 1:51 AM UTC. Galaxy Research later revised that figure to approximately 594 BTC, or around $38M, across roughly 500 addresses, suggesting some initial tallies captured transactions that were not all attributable to the exploit.

What actually went wrong

The flaw lived in the random number generation process that Coldcard Mk3 devices used to build recovery seeds. In plain terms: the seeds were not actually random.

The compromised firmware builds dated back to March 2021, which means wallets created during that window were vulnerable for over five years before the exploit landed.