BREAKING
Sep 3A Blockchain Just Hit Undo on Two Hours of Everyone's TransactionsSep 3You Did Everything Right and Lost It Anyway: The $116M Coldcard HackSep 3Ledger Is Getting Sued for $500M — and Not a Single Private Key Was HackedJul 8Trump Says Iran Ceasefire Is 'Over' — $450M in Crypto Liquidated in HoursJul 8The SEC Just Surrendered: Startups Can Now Raise $75M in Crypto Without Getting SuedJul 7The U.S. Has $20 Billion in Bitcoin and Nobody's in Charge of ItJul 7Strategy Sold 3,588 Bitcoin at a $15,000-Per-Coin Loss — to Pay Its Own DividendsJul 6A Hacker Borrowed $65 Million, Gave It All Back, and Kept $6 MillionJul 6Someone Spent $4M to Vote $20M Out of BonkDAO's Treasury — And It Was All 'Legal'Jul 5Trump Pocketed $636M. The 988,905 People Who Bought His Meme Coin Lost $3.8 Billion.Sep 3A Blockchain Just Hit Undo on Two Hours of Everyone's TransactionsSep 3You Did Everything Right and Lost It Anyway: The $116M Coldcard HackSep 3Ledger Is Getting Sued for $500M — and Not a Single Private Key Was HackedJul 8Trump Says Iran Ceasefire Is 'Over' — $450M in Crypto Liquidated in HoursJul 8The SEC Just Surrendered: Startups Can Now Raise $75M in Crypto Without Getting SuedJul 7The U.S. Has $20 Billion in Bitcoin and Nobody's in Charge of ItJul 7Strategy Sold 3,588 Bitcoin at a $15,000-Per-Coin Loss — to Pay Its Own DividendsJul 6A Hacker Borrowed $65 Million, Gave It All Back, and Kept $6 MillionJul 6Someone Spent $4M to Vote $20M Out of BonkDAO's Treasury — And It Was All 'Legal'Jul 5Trump Pocketed $636M. The 988,905 People Who Bought His Meme Coin Lost $3.8 Billion.
BTC -- --%
ETH -- --%
Fear & Greed F&G 65 Greed
ESC
Type to search articles
You Did Everything Right and Lost It Anyway: The $116M Coldcard Hack
BREAKING

You Did Everything Right and Lost It Anyway: The $116M Coldcard Hack

The Grind Catch-Up: we were offline for most of July and August. This series covers what you missed, in the order it mattered. Part 1 of 8.

Here’s the nightmare scenario nobody games out: you follow every rule. Hardware wallet. Air-gapped signing. Seed phrase stamped into steel and buried somewhere only you know. You never touched a sketchy dApp, never signed a blind transaction, never typed twelve words into a website.

And you still get cleaned out.

That’s what happened to more than 5,200 Coldcard addresses starting July 30, 2026. Attackers drained roughly 1,816 BTC — about $116 million — across four waves. The first wave alone took 1,083 BTC from 1,196 addresses in roughly 41 minutes, according to TRM Labs.

Nobody touched the devices

This is the part that makes it genuinely frightening. There was no supply chain interception, no evil maid, no $5 wrench. The attackers never came near the hardware.

The flaw lived in firmware — present since version 4.0.0 in March 2021. During key generation, the device bypassed its dedicated hardware randomness chip and fell back to a predictable software substitute. The whole premise of a hardware wallet is that the secure element rolls dice you cannot predict. These devices stopped rolling real dice and started following a pattern.

Once someone worked out the pattern, they could reproduce it offline: generate candidate seed phrases on their own machine, check them against the chain, and sweep whatever unlocked. No device access required. No user error required. As Fortune reported, victims had done nothing wrong at all.

If you generated a seed on a Coldcard between March 2021 and the patch, treat it as compromised and migrate to a new seed — not a new device, a new seed. The entropy is the problem, not the plastic.

Investigators have not publicly attributed the theft to a specific actor.

Why This Matters for Crypto Jobs

This is the clearest signal yet about where security hiring is going, and it is not toward more Solidity auditors.

The bug was not in a smart contract. It was in firmware, in an RNG path, sitting undetected in shipped hardware for five years. That is an embedded systems problem and a cryptographic engineering problem. The crypto industry has spent a decade building an audit industry pointed almost entirely at on-chain code, while the thing actually holding the keys got comparatively little scrutiny.

Expect demand to rise sharply for:

  • Embedded / firmware security engineers — people who can audit an RNG path, reason about entropy sources, and read a secure element datasheet
  • Cryptographic engineers who can spot a weak key-derivation pipeline before it ships
  • Hardware supply chain and release engineering — because “when did this regression enter the build?” took five years to answer
  • Reproducible build specialists — firmware you cannot independently rebuild is firmware you are trusting on vibes

These roles pay well and the talent pool is thin, because they draw from embedded systems and applied cryptography rather than the usual Web3 pipeline. If you have a background in device firmware or crypto implementation and you have been wondering whether it transfers to this industry: it transfers, and the industry just learned it the expensive way.

The uncomfortable lesson of 2026 so far is that the attack surface moved. It is in the firmware, the build pipeline, the customer database, and the governance process — everywhere except the audited contract everyone keeps auditing.


Looking for security roles in crypto? Browse open blockchain security, auditing, and infrastructure jobs at cryptogrind.com.

How did this hit?

Discussion

Comments are powered by GitHub. Sign in with your GitHub account to chime in.

Related jobs on Cryptogrind

View all

Looking for your next crypto role?

Browse hundreds of Web3 and crypto positions on Cryptogrind — from smart contract engineers to DeFi analysts.

Browse jobs