The pitch behind hardware wallets like Coldcard has always been simple: take your bitcoin offline onto a device that never touches the internet, and no hacker can get near it. That pitch took a battering last week - and the fallout says as much about crypto custody insurance as crypto security.
Canadian manufacturer Coinkite disclosed on July 30 that a coding error from a March 2021 firmware update had quietly been generating predictable wallet seeds - the master password behind every coin in the wallet - on some Coldcard devices. Instead of pulling genuine randomness from the device's hardware chip, the flawed firmware leaned on a software process that could be reverse-engineered from outside the device entirely.
The attack came in fast waves. On July 30, someone drained roughly 594 BTC (about $38 million) from nearly 500 dormant wallets in under half an hour, according to Block's engineering team. By August 1, Galaxy Research put the total at around 1,159 BTC (~$75 million). By Monday August 3, Bloomberg reported the tally had climbed to roughly 1,367 tokens - close to $86 million - from over 4,500 wallets.
The cause: affected firmware skipped the hardware random number generator, falling back on a predictable software substitute partly seeded by non-secret data like the device's serial number. On the worst-hit Mk3 units, that shrank the effective guesswork needed from an industry-standard 128 bits of entropy to around 40 - a different order of magnitude. Mk4, Mk5 and Q devices on older firmware are touched too, Coinkite says, though less severely.
🚨 A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained.
— Galaxy Research (@glxyresearch) August 1, 2026
Our estimated observed size of the Coldcard hack is now 1,367.05 BTC (~$88.6m) across 4,585 addresses.
More updates in the thread below 👇 https://t.co/hPtXh9444D pic.twitter.com/g6xA4OOi2f
Patched firmware is now out for every affected model; TAPSIGNER, OPENDIME and SATSCARD weren't affected. The catch: updating firmware doesn't fix a seed already generated on a dodgy version - those funds need moving to a brand new wallet, seed and all.
For a market still building its appetite for crypto risk, this is an awkward one - not because of the size, but because of where the failure sat. Cold storage is the gold-standard control against theft in specialty underwriting; Lockton's own guidance on the specie and crime markets defines it by the "air-gap" between device and internet. Coldcard owners had that air-gap. Didn't matter - the weakness was baked into the key before it was ever generated, not in how it was later stored.
That distinction matters at claims stage. Cyber insurance is generally built around data breaches, ransomware and business interruption, not private-key theft, which typically sits with crime or specie policies instead. But as Howden sets out, specie cover for digital assets has historically centred on named perils - fire, flood, theft, employee dishonesty - not a latent bug in a manufacturer's own random number generator. Whether this flaw falls neatly inside existing wordings, or drops into a gap between crime, specie and cyber, is what claims teams are about to find out.
Custody and key-management failures, not flashy smart contract exploits, are increasingly the industry's biggest loss driver. TRM Labs found infrastructure and key compromises made up around 15% of crypto hacking incidents in H1 2026 but drove roughly three-quarters of total losses, per Bloomberg's reporting. Blockaid's Ido Ben-Natan has flagged the same trend, noting most 2026 losses started at the key-generation stage rather than in smart contract code - exactly where Coldcard's flaw sat.
Timing-wise, it's inconvenient. The FCA confirmed crypto firms can start applying for authorisation under the UK's new cryptoasset regime from September 30, 2026, with the full framework binding from 25 October 2027. Insurance Business has previously covered how the UK market has been building capability to serve crypto custodians, and how regulators are tightening expectations on third-party risk generally - a framing that fits wallet-manufacturer firmware just as well as it fits a cloud provider.
For underwriters, "self-custody" and "cold storage" aren't the same as "no residual risk" - they just move the risk somewhere else, here into five-year-old firmware. For brokers, it's a nudge to check which policy, if any, actually responds when the loss comes from a defect built into the client's kit long before they bought it.
What to ask crypto-holding clients now