Coldcard Wallet Hack Hits $114M Losses, Flip Bitcoin Golden Rule
Coldcard Mk3 hardware wallets made by Coinkite were affected by a firmware bug introduced in a March 2021 update, reducing seed-phrase entropy and enabling automated sweeps. Since July 30, about 1,816 BTC (about $114M) was stolen from 5,200+ addresses in four waves, according to Galaxy Research. Coinkite issued patches; users are advised to move funds to new seeds.
How this was made

The 30-second read
Why it matters
The immediate tradable signal is BTC flow behavior: large sweeps from many addresses plus a surge in small-holder exchange deposits, alongside a modest BTC price dip.
Market read
A concrete, multi-wave BTC theft event is paired with contemporaneous exchange-deposit and price reaction signals, which can drive short-term BTC positioning and volatility.
What to watch
Attribution is unconfirmed and the article does not quantify how much of the swept BTC is ultimately sold versus moved/held, which can materially change price impact.
Background
Coldcard Mk3 wallets reportedly had a 2021 firmware bug that reduced seed-phrase entropy, later exploited via automated seed-guessing and sweeps.
Ticker impact
The article estimates 1,816 BTC swept from 5,200 addresses and notes a weekend dip below $63,000 as exchange deposits surge.
Near-term BTC volatility likely elevated, with downside risk if exchange-deposit panic continues; upside depends on whether users successfully rotate to safer custody.
The text provides concrete on-chain theft magnitude, timing by waves, and a contemporaneous BTC price dip plus exchange-deposit behavior, but lacks confirmation of broader protocol or sustained sell pressure beyond deposits.
Market effects
Highlights hardware-wallet firmware integrity and supply-chain risk, potentially increasing demand for patched devices and multisig/passphrase practices.
No clear regional linkage beyond global crypto market reaction.
Large theft scale and exchange-deposit behavior can influence global BTC liquidity and derivatives positioning.
Counterpoint
The hack did not break Bitcoin’s protocol, and the article frames exchange deposits as defensive evacuation rather than confirmed selling, which may limit sustained downside.
Key entities
- companyColdcard (Coinkite)
Hardware wallet maker whose Mk3 firmware bug allegedly enabled predictable seed generation and subsequent automated BTC sweeps.
- research/analystGalaxy Research (Alex Thorn)
Tracked the attack in real time and described the four sweep waves and RBF-related timing.
- research/analystCryptoQuant (Julio Moreno)
Reported on-chain transfer and exchange-deposit behavior compared with the FTX bankruptcy panic period.

