When hardware security fails, money moves. That appears to be the lesson from a significant vulnerability disclosed in older Coldcard hardware wallets in late July 2026, which sent a wave of capital flowing into spot Bitcoin ETFs including $IBIT, $FBTC, $BITC, $ARKB, and $MSBT, with combined daily inflows totaling $620 million following the breach.

What actually happened with Coldcard

On July 30, 2026, Coinkite, the Canadian company behind the Coldcard hardware wallet, disclosed a firmware vulnerability affecting older models, including the Mk3 series.

The flaw was not about someone physically stealing a device. It was subtler and, in some ways, scarier. The vulnerability reduced the entropy used during seed phrase generation to approximately 40 bits. In English: the randomness baked into creating a wallet’s master key was dramatically weaker than it should have been, making it mathematically feasible for an attacker to reconstruct private keys from scratch.

Galaxy Research estimated that between 1,367 and 1,816 BTC were drained from over 5,200 wallet addresses in the days following the exploit’s discovery. At prices prevailing around the time of the breach, that translates to roughly $89 million to $116 million in losses.