Security Hub

Coldcard Exploit Sparks $90M Bitcoin Flight From Cold Storage

Published: Aug 2, 2026By Aleksandar Dukic

Key Analysis

A Coldcard hardware wallet exploit tied to a $90M Bitcoin loss has rattled self-custody users. Here is what happened and how to check your own setup.

Coldcard Exploit Sparks $90M Bitcoin Flight From Cold Storage

Listen To This Article

Coldcard Exploit Sparks $90M Bitcoin Flight From Cold Storage

4m 42s audio

AI narration. Useful for scanning on the move. Names and tickers may be mispronounced.

A loss of roughly $90 million in Bitcoin from cold storage has moved hardware wallet security to the front of the week's crypto news, according to Cointelegraph's Hodler's Digest for August 2. The incident lands while Bitcoin trades at $63,445, up 1.1% over 24 hours as of August 2, 2026, with the Fear and Greed Index reading 35 (Fear). The damage was not to an exchange or a hot wallet. It hit funds people believed were sealed offline.

Cold storage is supposed to be the safe end of the spectrum. Keys never touch an internet-connected device, so remote attackers have nothing to reach. The reason this loss stings is that it undercuts that assumption for a device many holders treated as a final line of defense.

The specific failure matters more than the headline number

Hardware wallets fail in a handful of well-understood ways, and the fix depends entirely on which one is in play. A weak or predictable seed generation process lets an attacker reconstruct private keys without ever touching the device. A tampered or counterfeit unit can leak a seed at setup. A backup written to a phone photo or a cloud note turns an offline key into an online one. Physical theft plus a known PIN weakness does the rest.

This episode connects to an earlier warning. In July, Coldcard told Mk3 owners to move funds after a theft of 594 BTC was linked to how some older units handled seed material. A $90 million figure at current prices implies a much larger pool of coins than a single 594 BTC event, so the safe read is that this is a cluster of losses tied to the same class of weakness rather than one wallet emptied in one transaction. Anyone still holding on affected hardware should treat migration as urgent, not optional.

Self-custody shifts the risk, it does not delete it

Custodial products carry counterparty risk. If the company holding your coins fails, as FTX and Celsius showed, your balance can be frozen or gone. Self-custody removes that party from the equation. The trade is that you inherit every job the custodian used to do: generating entropy correctly, storing the backup safely, and verifying the device is genuine.

For anyone spending crypto directly from their own wallet, the same logic applies to self-custody card options. A non-custodial card that pulls from a wallet you control avoids the insolvency risk that froze funds at failed lenders. It does not protect you if the seed behind that wallet was compromised at the source. The security surface simply moves from the provider's balance sheet to your own key management.

Checking your own setup

Owners of any hardware wallet, not only Coldcard, can take a few concrete steps this week. Verify the firmware version against the manufacturer's published releases and confirm the device is running the latest signed build. Confirm that your seed backup exists only on physical media, never a screenshot, cloud drive, or password manager entry. If you bought the unit secondhand or through a non-official reseller, assume it could be compromised and move funds to a freshly initialized device with a newly generated seed.

Vendors that sell branded hardware alongside spending products, including Ledger, tie their card and wallet ecosystems to the same seed security model, so a compromised backup affects both the stored coins and any card drawing on that wallet. The defense is boring and it works: generate the seed on a trusted device, write it down offline, and never let a photo of it exist.

The week's other threads

The Hodler's Digest also flagged the CLARITY Act reaching a Senate deadline before the August recess, and described the broader market as being in a consolidation phase that some traders read as constructive. Neither of those moved prices sharply. Bitcoin's 1.1% daily gain sits against a 2.85% decline over the past week, which fits the "consolidation" framing more than a breakout.

Security stories rarely move the tape the way an ETF approval does. They matter because they change behavior. A $90 million reminder that offline does not mean invulnerable will push some holders to audit their setups, and that is the right response.

Overview

A Coldcard-linked exploit tied to roughly $90 million in Bitcoin losses from cold storage headlined the week's crypto news as of August 2, 2026, with BTC at $63,445 and sentiment in Fear at 35. The loss connects to a July warning to Coldcard Mk3 owners after a 594 BTC theft. Cold storage removes exchange and remote-attacker risk but not the risk of a weak seed, a tampered device, or a backup that leaked online. Self-custody shifts responsibility to the user rather than eliminating danger. The practical response is to verify firmware, confirm seed backups live only on offline media, and migrate off any device bought through unofficial channels.

DisclaimerThis article is provided for informational purposes only and does not constitute financial advice. All fee, limit, and reward data is based on issuer-published documentation as of the date of verification.
Updated: Aug 3, 2026

Have a question or update?

Discuss this analysis with the community on X.

Discuss on X

Comments

Comments are moderated and may take a moment to appear.