COLDCARD destroys inventory tied to breach, brings in law enforcement

The August 3, 2026 update confirms a containment response but leaves the attack surface, affected batch count and customer checks still undisclosed.

Summary

COLDCARD said on August 3, 2026 that it destroyed all inventory linked to a recent security breach and is cooperating with law enforcement to identify those responsible. The response signals a containment effort rather than a recall, with the company opting to eliminate flagged stock instead of quarantining or reworking it. The statement does not explain how the inventory was compromised or whether the issue involved the supply chain, firmware, fulfillment or another part of the process. It also does not disclose how many units were affected, a date range or batch identifiers, leaving the scope undefined until the company issues a fuller post-mortem. The update matters because hardware wallets depend on users trusting that a device has not been altered before it reaches them. Coming weeks after COLDCARD's July warning to Mk3 owners tied to a theft of hundreds of Bitcoin involving seed handling on older devices, the latest incident underscores that self-custody removes counterparty risk but still requires device and setup verification. Owners are advised to confirm firmware signatures (cryptographic authenticity checks) on device, generate seeds on the hardware rather than importing them, buy only through the manufacturer or an authorized reseller, and monitor COLDCARD's official channels for further details.

Terms & Concepts
  • firmware signatures: Cryptographic checks proving device software is authentic.
  • self-custody: Holding and controlling your own crypto keys.
  • cold storage: Keeping crypto offline for stronger security.