30 July 2026
Roughly 1,816 BTC — about $116m — was drained from more than 5,200 addresses in four waves. The cause was not a new attack on the device but a firmware bug shipped in March 2021 that cut seed entropy from 128 bits to as little as 40, making those keys brute-forceable with no physical access at all. It is the largest hardware-wallet loss ever recorded.
What that does and does not say
It does not say the design was wrong. Coldcard still has the most rigorous threat model in this table: two secure elements from different manufacturers, PIN verified in hardware, duress PINs, decoy wallets, brick-me options and documentation that explains its assumptions in unusual detail. It says that five years of correct design can be undone by one release, and that this table scores the shipped record rather than the intent.
If you own one
Seeds generated under the affected 2021 firmware have to be regenerated and the funds moved — that is the vendor's own guidance, and it is not optional. A device set up outside that window is unaffected.
Who it was for
Bitcoin holders who want fully air-gapped signing through microSD or NFC and are comfortable with an uncompromising interface. That case still stands; the 2026 record now stands next to it.