Coldcard Bitcoin Hack - What You Need To Know & Options for Recovery

Published August 10, 2026
0 min read
Refundee
refundee.com
Share
Case updates
The latest on this case from our team.
0 updates
No items found.

Since 30 July 2026, attackers have reportedly been exploiting a firmware defect in Coldcard hardware wallets, devices made by Canadian manufacturer Coinkite.

Recent on chain analysis, referenced by legal specialists working with affected victims, points to losses climbing towards an estimated $116 million, with more than 5,200 individuals affected and roughly 1,816 BTC moved.

Refundee is supporting specialist law firm EMM Legal to raise awareness of the Coldcard hack, identify affected victims, and assess possible avenues of recovery.

We're keen to speak with anyone who may have been impacted. Victims can start their Coldcard claim today for a free, no-obligation assessment of their recovery options.

Potential routes to recovery include:

  • Traditional blockchain tracing and asset recovery targeting the bad actor(s), which can proceed almost anywhere in the world.
  • The second, according to legal analysis published by specialist crypto litigation and law firm EMM Legal, is a potential claim against Coinkite itself. As a Canadian incorporated manufacturer, this kind of claim would typically need to be pursued in Canada.

Submit Your Enquiry Here

Refundee’s co-founder, Will Ayles, said: “We know the hack will have devastated thousands of people, and if we’re able to use our platform to connect people and find a solution then we want to help. It aligns with our mission of helping victims of fraud when they need it most”.

How the Coldcard Hack Happened:

According to legal specialists reviewing the incident, the vulnerability traces back to March 2021.

Coldcard devices are designed to generate their wallet seed using a hardware random number generator drawing on genuine physical randomness.

Reports indicate that the issue arose during a routine software library migration. That migration is understood to have introduced two different methods of generating randomness that looked identical from the outside, one tied to the device's real hardware source, the other a fallback method designed for boards that lacked the proper hardware component.

A misconfigured setting in the build process meant it only checked for the presence of the hardware, not whether the device was actually on. The build could therefore complete successfully while seed generation silently defaulted to the weaker, predictable generator.

Affected devices produced seeds following a discoverable pattern and attackers who identified this pattern were reportedly able to reconstruct victims' seed phrases and drain their wallets, without ever needing physical access to the device itself.

Coinkite has since released fixed firmware and published a security advisory urging affected owners to update their device and move their funds to a newly generated seed.

How the Attacks Unfolded

The vulnerability is understood to have led to a wave of attacks in which hackers gained access to Bitcoin wallets without needing physical possession of the device.

According to legal specialists, an estimated $116 million, with more than 5,200 individuals have been affected and roughly 1,816 BTC moved.

Reports indicate the theft unfolded in coordinated waves rather than as a single event, starting with a sweep on Thursday 30 July that drained hundreds of wallets within minutes. Further waves followed over the succeeding days as attackers worked through the pool of vulnerable addresses.

Much of the stolen Bitcoin is understood to have since been consolidated into a small number of unspent addresses, which specialist investigators say can make it easier to monitor and, in some circumstances, act on if those funds are moved.

What To Do If You’ve Been Affected By the Coldcard Hack

If you’ve been the victim of the coldcard hack, do not blame yourself, there are steps you can take quickly, but calmly.

  • Update your firmware to the latest version via Coinkite's official channels before doing anything else with the device.
  • Generate a brand new seed on the updated firmware - the old one should be treated as compromised, even after the update.
  • Move your funds to the new seed, testing with a small transaction first before transferring the full balance.
  • Keep the old backup safe until you've confirmed the full balance has arrived and the migration is complete.

Important to note: Users should never share their seed phrase with anyone who claims to be an expert in moving funds or recovering them. These types of scams are regularly followed up by recovery, impersonation and phishing scams.

Can My Stolen Bitcoin Be Recovered?

Recovery isn't guaranteed, and every case is different, but victims of the Coldcard hack may have options available to recover their stolen Bitcoin.

Two potential routes to recovery:

  • Blockchain tracing and asset recovery.
    • The first is traditional blockchain tracing and asset recovery targeting the bad actor(s), which can proceed almost anywhere in the world.
  • Holding Coinkite liable
    • The second, according to legal analysis published by specialist crypto litigation and law firm EMM Legal, is a potential claim against Coinkite itself. As a Canadian incorporated manufacturer, this kind of claim would typically need to be pursued in Canada.

How Refundee Can Help:

Refundee is supporting specialist law firm EMM Legal to raise awareness of the Coldcard hack, identify affected victims, and assess possible avenues of recovery.

Refundee can assess your case and, where relevant, link you to a specialist law firm, EMM Legal, which specialises in large-scale cryptocurrency cases such as this.

We have worked closely with EMM Legal previously and are currently assessing claims on behalf of those affected by the Coldcard hack.

We have found EMM Legal to be high quality and reputable, however, you should perform your own research and options before appointing them on your own behalf.

If you have lost bitcoin through the Coldcard hack, please complete our specific claim form below for an assessment of the next steps.

Refundee Ltd is authorised and regulated by the Financial Conduct Authority (FRN: 937096).

Submit Your Enquiry

Either claim avenue, if progressed by the lawyers will likely incur fees depending on which action is recommended. No charges apply for enquiring.

More about Refundee

Here are the technical bits:

Refundee Ltd is a claims management company authorised and regulated by the Financial Conduct Authority in respect of regulated claims management activity FRN: 937096.

Registered with the Information Commissioner's Office; registration number: A8986071.

Registered office address: Refundee, 3rd Floor, 86-90 Paul Street, London, EC2A 4NE.

Registered as a company in England & Wales; number: 12855931.

Frequently asked questions

How much Bitcoin has been stolen in the Coldcard hack?
What should I do if I own a Coldcard?
Can I get my stolen Bitcoin back?
Refundee
refundee.com
Share
Summary

Did you lose Bitcoin in the Coldcard hack? Refundee is looking to speak with anyone who may have been impacted. Victims can start their Coldcard claim today for a free, no-obligation assessment of their recovery options.

It's free to find out if we can help
We've already helped over {{total-customers-text}}  people recover {{money-recovered-text}},  and we're ready to help you too.
It's free to find out if we can help

We've already helped over 
{{total-customers-text}}
 people recover 
{{money-recovered-text}}
 and we're ready to help you too.