Coldcard Bitcoin Hack - What You Need To Know & Options for Recovery

Since 30 July 2026, attackers have reportedly been exploiting a firmware defect in Coldcard hardware wallets, devices made by Canadian manufacturer Coinkite.

Estimates of the scale have shifted as the incident has developed. Early figures from blockchain security firm Galaxy Research put losses above $130 million. 

More recent on chain analysis, referenced by legal specialists working with affected victims, points to losses climbing towards an estimated $116 million, with more than 5,200 individuals affected and roughly 1,816 BTC moved. 

Refundee is supporting specialist law firm EMM Legal to raise awareness of the Coldcard hack, identify affected victims, and assess possible avenues of recovery. 

We're keen to speak with anyone who may have been impacted. Victims can start their Coldcard claim today for a free, no-obligation assessment of their recovery options.

Potential routes to recovery include:

  • Traditional blockchain tracing and asset recovery targeting the bad actor(s), which can proceed almost anywhere in the world.

  • The second, according to legal analysis published by specialist crypto litigation and law firm EMM Legal, is a potential claim against Coinkite itself. As a Canadian incorporated manufacturer, this kind of claim would typically need to be pursued in Canada.

Submit Your Enquiry Here

Refundee’s co-founder, Will Ayles, said: “We know the hack will have devastated thousands of people, and if we’re able to use our platform to connect people and find a solution then we want to help. It aligns with our mission of helping victims of fraud when they need it most”. 

How the Coldcard Hack Happened:

Coldcard wallets are designed to generate a highly random "seed phrase," essentially the master password to a Bitcoin wallet, and store it entirely offline.

Coinkite has confirmed that certain versions of its firmware contained a flaw in how seed phrases were generated, making some of them vulnerable to attack. 

According to legal specialists reviewing the incident, the underlying cause traces back to a firmware update from March 2021, in which a software update accidentally caused some devices to rely on a weaker, more predictable method of generating seed phrases instead of the intended hardware based process. 

Reports indicate the build process only checked whether the stronger method was present, not whether it was actually switched on, allowing the issue to go undetected for several years.

Attackers who identified this flaw were reportedly able to reconstruct victims' seed phrases and drain their wallets, without ever needing physical access to the device itself.

It has not been confirmed how the flaw was identified, though Coinkite has suggested AI may have been used to find the issue, despite an earlier AI review having failed to detect it.

How the Attacks Unfolded

The vulnerability is understood to have led to a wave of attacks in which hackers gained access to Bitcoin wallets without needing physical possession of the device.

According to legal specialists, an estimated $116 million, with more than 5,200 individuals have been affected and roughly 1,816 BTC moved. 

Reports indicate the theft unfolded in coordinated waves rather than as a single event, starting with a sweep on Thursday 30 July that drained hundreds of wallets within minutes. Further waves followed over the succeeding days as attackers worked through the pool of vulnerable addresses.

Much of the stolen Bitcoin is understood to have since been consolidated into a small number of unspent addresses, which specialist investigators say can make it easier to monitor and, in some circumstances, act on if those funds are moved.

Why This Differs From a Typical Fraud Case

This case is different from usual phishing or Authorised Push Payment Fraud cases where victims were not tricked or manipulated into handing over their crypto.

What has drawn attention to this case is that many of the people affected followed standard offline-storage practices in keeping their device disconnected from the internet and not sharing their seed phrase with anyone, yet were still exposed, based on where the issue is reported to have originated.

Coinkite has since released fixed firmware and published a security advisory urging affected owners to update their device and move their funds to a newly generated seed.

What To Do If You’ve Been Affected By the Coldcard Hack

If you’ve been the victim of the coldcard hack, do not blame yourself, there are steps you can take quickly, but calmly.

  • Update your firmware to the latest version via Coinkite's official channels before doing anything else with the device.

  • Generate a brand new seed on the updated firmware - the old one should be treated as compromised, even after the update.

  • Move your funds to the new seed, testing with a small transaction first before transferring the full balance.

  • Keep the old backup safe until you've confirmed the full balance has arrived and the migration is complete.

Important to note: Users should never share their seed phrase with anyone who claims to be an expert in moving funds or recovering them. These types of scams are regularly followed up by recovery, impersonation and phishing scams.

Can My Stolen Bitcoin Be Recovered?

Recovery isn't guaranteed, and every case is different, but victims of the Coldcard hack may have options available to recover their stolen Bitcoin. 

Two potential routes to recovery:

  • Blockchain tracing and asset recovery.

    • The first is traditional blockchain tracing and asset recovery targeting the bad actor(s), which can proceed almost anywhere in the world.

  • Holding Coinkite liable

    • The second, according to legal analysis published by specialist crypto litigation and law firm EMM Legal, is a potential claim against Coinkite itself. As a Canadian incorporated manufacturer, this kind of claim would typically need to be pursued in Canada.

How Refundee Can Help:

Refundee is supporting specialist law firm EMM Legal to raise awareness of the Coldcard hack, identify affected victims, and assess possible avenues of recovery. 

Refundee can assess your case and, where relevant, link you to a specialist law firm, EMM Legal, which specialises in large-scale cryptocurrency cases such as this.

We have worked closely with EMM Legal previously and are currently assessing claims on behalf of those affected by the Coldcard hack.

We have found EMM Legal to be high quality and reputable, however, you should perform your own research and options before appointing them on your own behalf. 

If you have lost bitcoin through the Coldcard hack, please complete our specific claim form below for an assessment of the next steps.

Refundee Ltd is authorised and regulated by the Financial Conduct Authority (FRN: 937096)

More about Refundee

Here are the technical bits:

Refundee Ltd is a claims management company authorised and regulated by the Financial Conduct Authority in respect of regulated claims management activity FRN: 937096.

Registered with the Information Commissioner's Office; registration number: A8986071.

Registered office address: Refundee, 3rd Floor, 86-90 Paul Street, London, EC2A 4NE.  

Registered as a company in England & Wales; number: 12855931.

Frequently Asked Questions (FAQ’s)

Next
Next

T4Trade Review - How to Recover Your Funds