Coldcard hardware wallet flaw enables theft of up to $89 million in Bitcoin
A software bug in Coldcard hardware wallets allowed attackers to siphon roughly $89 million in Bitcoin from more than 1,200 addresses within minutes.
Galaxy Research identified a swift Bitcoin drain on July 30, where more than 1,000 coins were moved from 1,196 Coldcard wallets in just 41 minutes, later estimating total losses near $89 million. The breach stems from a coding mistake in specific Coldcard firmware that weakened the randomness of recovery phrases, allowing sophisticated attackers to reconstruct them remotely. Coinkite released a software patch that secures newly created wallets, but the company stressed that updating firmware does not protect seeds already generated with the flawed code.
Users are instructed to create fresh recovery phrases with the updated firmware and transfer their holdings to the new wallets. CEO Rodolfo Novak expressed deep regret, urged rapid remediation, and pledged cooperation with investigators, including the FBI and Canadian authorities. Other crypto stakeholders, such as Bitkey developer Clay Garrett, clarified that separate issues do not pose similar risks.
Why it matters
A vulnerable hardware wallet exposed billions in crypto assets, highlighting risks in digital-currency security.
In this story