Coldcard Vulnerability Linked to Massive $115 Million Bitcoin Theft Campaign
KuCoin reports that a Coldcard-related exploit has been linked to a years-long Bitcoin theft campaign, with estimated losses now exceeding $115 million.

The case matters beyond Bitcoin: if you use hardware wallets, marketplace wallets, or sign transactions for NFT activity, a compromised seed-generation process can defeat your security before you ever approve a transaction.
The reported campaign is associated with a vulnerable Coldcard firmware release from March 17, 2021. According to the report, the stolen coins were created on the same day, pointing investigators toward a seed-generation flaw. That type of flaw can make wallet seed entropy—the randomness used to create a recovery phrase—predictable or forgeable.
The reported attack pattern
KuCoin says Galaxy Research spoke with more than 200 victims on August 16 while examining the campaign. The investigation identified 8,680 addresses in a published theft set, although only a small portion could be directly connected to people who reported losses.
The figures vary depending on which address set is counted. The published dataset reportedly includes roughly 1,790 addresses holding about 714.8 BTC, while the wider theft set is associated with approximately 1,778.6 BTC. Another estimate cited in the report put the losses above 1,596 BTC across roughly 7,300 addresses. Based on Bitcoin’s price on August 16, the reported total exceeded $115 million.
Do not treat those totals as a single reconciled audit. They are estimates from different address groups and attribution methods. The important security signal is the timing: the campaign appears to have targeted wallets created during or after the vulnerable firmware period, rather than relying only on phishing or a user approving a malicious NFT transaction.
Investigators also identified transaction fingerprints, including block timing, fees, lock times, replacement settings, transaction structure, and destination-address behavior. One reported wave moved about 1,082.65 BTC from blocks 960,183–960,191, generally routing one victim per transaction into four collection addresses. Other clusters used different batching and dispersal patterns.
Your mitigation protocol
1. Identify your firmware exposure.
Check whether your Coldcard was running the vulnerable firmware when the wallet was created. Do not assume that updating the device later repairs a seed that was generated under flawed conditions. The recovery phrase is the security boundary; a device update cannot make a compromised phrase trustworthy.
2. Isolate funds tied to the affected setup.
If your wallet may fall within the reported exposure, stop using the seed for Bitcoin or any other asset. Do not connect it to an NFT marketplace, sign a listing, or approve another transaction from it while you investigate.
3. Move assets to a newly generated wallet.
Generate a replacement wallet using a device and firmware state you have independently verified. Record the new recovery phrase offline. Never reuse the old phrase, and never enter either phrase into a website, browser extension, support form, or online “checker.”
4. Audit every address, not only the current balance.
Review historical receiving addresses and transaction activity. A wallet showing no obvious theft today is not automatically safe. Look for unauthorized transfers, unexpected consolidation, or destinations you do not recognize.
5. Revoke and replace access where applicable.
If the same seed, backup, or signing setup was used with marketplace accounts or other wallets, isolate those accounts and replace the affected credentials. For NFT users, separate high-value assets from daily trading wallets and verify every destination before signing.
What to watch next
The investigation described by KuCoin is still an attribution exercise, not a substitute for a wallet-by-wallet audit. Address clusters can reveal transaction behavior, but they do not automatically prove who controlled every address or which victims are included in each estimate.
You should also treat this incident as part of a broader exploit environment. Other source reports describe a Maya Protocol exploit that allegedly halted the network after $1.4 million in BTC was stolen, while CryptoRank reported a proposed Harmony rollback after counterfeit ONE tokens were minted. These are separate incidents, but they reinforce the same operational rule: isolate affected systems first, then verify the scope before resuming activity.
Mandatory security checklist:
- Verify the firmware used when your wallet seed was created.
- Isolate any seed connected to the reported exposure.
- Generate a new wallet; do not “refresh” the old one.
- Transfer funds only after independently checking the new address.
- Audit historical transactions and all connected marketplace accounts.
- Revoke old permissions and separate trading wallets from long-term storage.
- Never disclose a recovery phrase, even to supposed device support.
- Do not resume signing until the wallet’s origin and transaction history are verified.