Hackers exploit Coldcard wallet flaw to steal over $100 million in Bitcoin
Hackers exploited a firmware bug in Coinkite's Coldcard hardware Bitcoin wallets, which are considered the safest offline storage. The flaw, present since March 2021, caused seed phrases to be generated with insufficient randomness, allowing attackers to guess them. Over 1,800 Bitcoin (worth ~$116 million) were stolen from more than 5,200 wallets in ongoing attacks. The breach undermines trust in cold storage security and has impacted federal investigators and compliance firms. Coldcard released a fix but warned compromised seeds cannot be repaired.
Editorial responsibility
- No named human review is recorded for this page.
- Reports are grouped by semantic similarity and deterministic rules. Language models may assist titles, summaries, translation and cross-source analysis; the page itself is projected from evidence records.
- Current automated evidence projection
Cross-source coverage
Common ground
- The Coldcard hack was caused by a firmware bug that made seed phrases guessable, which is a serious quality assurance failure.
- The Bitcoin network and its underlying cryptography were not compromised; the flaw was specific to one vendor's product.
- Victims of the hack have little to no recourse, and the crypto industry lacks consumer protections like deposit insurance or legal accountability.
- The industry's pattern of responding to hacks with 'you should have done X differently' places too much burden on individual users.
Points of contention
- Whether this hack proves self-custody is fundamentally flawed or just shows a vendor-specific failure.
- Whether a 1-2% failure rate in a security product is a sign of systemic collapse or a manageable vendor risk.
- Whether regulation would have prevented the bug or if market solutions like multi-signature defaults and insurance are more effective.
- Whether the solution is to abandon self-custody or to demand better standards and accountability from hardware wallet makers.
Blind spots
- Neither side fully addressed how to make self-custody more accessible and safer for average users, not just security experts.
- The debate didn't explore whether hardware wallet manufacturers should be legally required to carry insurance or submit to mandatory audits.
- There was little discussion of how the crypto industry could create a compensation fund for hack victims without relying on regulation.
WorldAttention’s read
The Coldcard hack exposed a serious vendor failure, not a flaw in Bitcoin or self-custody itself. Both sides agree that the industry needs better accountability and consumer protections, but they disagree on whether this means self-custody is broken or just needs stronger standards. The real blind spot is how to make self-custody safe and simple for everyday users, not just experts. Moving forward, the industry should focus on mandatory multi-signature defaults, vendor liability, and insurance products—rather than abandoning the idea of holding your own keys.
Wire timeline
Coldcard Bitcoin Hack Exposes Flaw in Hardware Wallet Seed Phrase Generation
A security lapse at Coldcard, a hardware wallet manufacturer, allowed hackers to steal at least $100 million in Bitcoin from users. Unlike typical crypto hacks targeting insecure platforms or altcoin traders, this breach affected security-conscious Bitcoin owners who used cold storage and followed best practices. The vulnerability stemmed from a non-randomized seed phrase generation process, enabling hackers to guess other phrases from a sample. While Coldcard holds less than 2% of the hardware wallet market and the broader crypto market was unaffected, the incident is seen as a symbolic crisis of faith for Bitcoin purists. The article argues the fault lies with the manufacturer's negligence, not Bitcoin itself, and highlights the trade-off between self-custody and convenience.
Over $100 Million in Bitcoin Stolen Due to Coldcard Wallet Firmware Bug
A software flaw in Coldcard hardware wallets has enabled numerous hackers to steal over $100 million in bitcoin, according to crypto research firm Galaxy Research. The bug, present in firmware versions dating back to March 2021, caused the wallets to generate seed phrases with insufficient randomness, making them guessable. Galaxy Research identified 1,596 bitcoin (worth ~$102 million) stolen from over 7,300 wallets across three major attack waves and 14 smaller incidents. Coldcard maker Coinkite confirmed the bug and released a fix, but warned that compromised seeds cannot be repaired, urging users to migrate funds to new wallets. Notably, about 600 hacked addresses belonged to federal investigators and compliance firms. Total losses could reach 2,000 bitcoin (~$130 million) as victim addresses are still being compiled. The article also notes a separate bitcoin price dip to a three-week low amid Strategy's $5 billion sale plans.
Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit
On August 3, 2026, Fortune reported a major cryptocurrency security breach involving Coldcard cold storage wallets. Hackers drained approximately 1,816 Bitcoin (worth about $116 million) from 5,200 addresses. The exploit is particularly devastating because it targeted hyper-secure cold storage wallets, which are typically considered the safest method for storing cryptocurrency offline. The incident raises serious questions about the security of even the most protected crypto storage solutions and has sent shockwaves through the Bitcoin community. Details about the specific vulnerability exploited remain limited at the time of reporting.
Show 2 older updatesHide older updates
Hackers hit Bitcoin’s safest hiding place in ongoing attack
Hackers have exploited a software flaw in Coinkite's Coldcard brand of 'cold' Bitcoin wallets, which are typically considered the safest form of cryptocurrency storage. The ongoing attack has resulted in the theft of approximately 1,367 Bitcoin tokens, valued at around US$86 million, from over 4,500 wallets. Cold wallets are offline storage devices designed to be immune to remote hacking, making this breach particularly significant. The incident highlights vulnerabilities even in hardware-based security solutions for cryptocurrency. The attack is ongoing, with tens of millions of dollars continuing to be siphoned from affected wallets.
Hackers exploit software flaw to drain millions from Bitcoin cold wallets
Hackers have exploited a software flaw in Coinkite's Coldcard brand of 'cold' Bitcoin wallets, siphoning tens of millions of dollars in an ongoing attack. Approximately 1,367 Bitcoin tokens, valued at around US$86 million, have been drained from over 4,500 wallets. Cold wallets are typically considered the safest storage method for cryptocurrencies as they are not connected to the internet. This breach undermines that security assumption, highlighting vulnerabilities in hardware wallet software. The attack is ongoing, with funds continuing to be stolen. The incident raises significant concerns about the security of cryptocurrency storage solutions and the potential for large-scale theft even from offline systems.