Crack in Coldcard Bitcoin Wallet Exposes Millions to Crypto Theft

Hackers have identified a software vulnerability in a particular brand of “cold” Bitcoin wallet, which is regarded as one of the most secure options for cryptocurrency storage. They are currently extracting tens of millions of dollars in a continuing assault. Late last week, Coinkite Inc., based in Canada, informed users of its Coldcard devices that a security vulnerability in the keys safeguarding their cryptocurrency had led to the compromise of certain wallets. By Monday, approximately 1,367 Bitcoin valued at around $86 million had been withdrawn from over 4,500 wallets, as reported. Coldcard is a brand of hardware device that enables users to safeguard their Bitcoin in what are referred to as cold wallets. These wallets are designed to be the most secure option for storing cryptocurrency, as they operate in isolation from the internet.

However, a flaw in the software of the Coldcard devices meant that the generated “seed phrase” — a long string of words used to gain access to a wallet — was predictable, according to a report from Block Inc.’s engineering team. “It exposes the fallacy of your crypto being offline,” said Aneirin Flynn. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.” For certain individuals, the reports of the attacks were initially beyond comprehension. Jonathan Goodman, one of the victims, stated that he initially believed it did not affect him; however, he decided to verify the contents of his wallet regardless.

“The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” he told. “Between 9:36 and 9:43 p.m. on July 29th, all three of my wallets were completely drained.” The crux of the matter revolved around Coinkite’s implementation of the random-number generator in the generation of the phrases, as noted by Block. True randomness is essential for ensuring cryptographic security; however, Coldcard wallets incorporated a fallback mechanism that led to the generation of keys based on deterministic values, including the device serial numbers. The outcome has been that attackers have successfully recalibrated and depleted user wallets in a systematic manner. Reports on Friday indicated losses of approximately $38 million; however, the figures escalated rapidly over the weekend.

In a statement on its website, Coinkite acknowledged that funds managed by seeds produced on the compromised firmware are exposed to potential risk. Fixed firmware is now available for all affected models and release tracks, it stated. The attack has garnered significant attention across digital platforms, with influencers and corporate executives contributing their perspectives on the potential ramifications. In 2026 to date, the volume of cryptocurrency theft has decreased compared to the previous year. The first half of the year has recorded total losses amounting to $972 million, which is less than half of the $2.3 billion that was stolen during the first half of 2025, as indicated by a TRM Labs report released last month. Nonetheless, the aggregate count of hacks surged to 207, marking the peak recorded in any six-month timeframe.