Monday, September 21, 2026

“Coldcard Bitcoin Wallet Breach: Hackers Steal $100M+”

Share

Coldcard, a bitcoin-only hardware wallet, has fallen victim to a data breach, with hackers reportedly siphoning over $100 million US worth of bitcoin from the wallets. Created by Coinkite, Coldcard does not store bitcoin but enhances security by storing “seed phrases” offline, ensuring an added layer of protection. These phrases act as a master key for the bitcoin-only wallet, allowing users to authorize transactions securely. The wallet, known for its “cold storage” feature, has been highly acclaimed by users and security experts for its secure storage of bitcoin.

The breach was caused by a software bug that allowed hackers to reconstruct wallet seed phrases, leading to multiple attacks where hackers accessed users’ bitcoin wallets without physical access to the device. As a result, approximately 1,596 bitcoin from around 7,300 addresses were stolen, with a potential increase to 2,055 bitcoin if a fourth wave of attacks is confirmed, totaling around $130 million US. The perpetrators behind these attacks remain unidentified.

Coinkite has issued firmware updates to address the vulnerability, urging users to transfer their funds immediately. The company acknowledged the flaw in the firmware, which relied on a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator. Coinkite advised against generating new seeds on affected devices until the update is installed.

Users are cautioned against keeping compromised wallets and are encouraged to install the latest firmware to safeguard against future breaches. Galaxy Research emphasized the importance of migrating funds to secure addresses at custodians or exchanges. The investigation continues, with efforts to recover funds and identify responsible parties underway.

Read more

Local News