Monday, August 17, 2026
HomeBusinessColdcard Hack: $100M Bitcoin Theft Exposes Vulnerability

Coldcard Hack: $100M Bitcoin Theft Exposes Vulnerability

If you are a user of bitcoin, chances are you are familiar with Coldcard, a hardware wallet dedicated to bitcoin that has recently fallen victim to a data breach.

According to Galaxy Research, hackers have managed to siphon off over $100 million US worth of bitcoin from Coldcard hardware wallets.

Here is what is known about the ongoing breach, its impact on users, and steps to protect your cryptocurrency.

Functionality of Coldcard

Created by Coinkite, a company based in Toronto, Coldcard is recognized as a hardware wallet for bitcoin. Unlike traditional wallets, Coldcard does not store bitcoin for users; instead, it enhances security by storing “seed phrases” offline within the physical device, isolated from the internet.

“Seed phrases” are complex sequences of random words that serve as a master key to the bitcoin-only wallet, enabling users to authorize and sign transactions securely.

Two types of Bitcoin wallets are displayed on a website.
Coldcard’s website showcases two bitcoin-only hardware wallets, developed by Coinkite, a Toronto-based company. (Coldcard.com)

Coldcard is promoted as a secure “cold storage” option for long-term bitcoin holders seeking offline key storage and has received accolades from users and security experts as one of the most reliable places to safeguard bitcoin.

Incident Overview

Coinkite recently alerted its users to a software bug that allowed hackers to reconstruct wallet “seed phrases,” leading to a significant vulnerability exploited in multiple attacks. This flaw permitted hackers to access users’ bitcoin wallets without physical access to the device.

As per Galaxy Research, the attacks have resulted in the theft of 1,596 bitcoin from around 7,300 addresses, with a potential total loss of 2,055 bitcoin, valued at approximately $130 million US if a suspected fourth wave is confirmed.

The culprits behind the attacks remain unidentified.

Rodolfo Novak, Coinkite’s co-founder and CEO, advised users who generated a seed with a Coldcard wallet to transfer their funds immediately following firmware updates issued for affected products, as stated in an advisory on the company’s website.

Novak expressed the company’s commitment to regain users’ trust despite the financial losses incurred.

Attempts to reach Coinkite for further comments by CBC News have not been successful.

In an update, Coinkite acknowledged that the flaw originated in March 2021, wherein affected firmware used a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator for wallet seed generation. The company destroyed remaining inventory with the vulnerable firmware and halted shipments upon confirming the vulnerability.

Novak also cautioned other developers about the risks associated with AI in code review processes, emphasizing the need for heightened vigil

RELATED ARTICLES

Most Popular