Coldcard Bitcoin Hack Surpasses $100 Million in Losses
A serious firmware flaw in Coldcard wallets has resulted in over $100 million worth of stolen Bitcoin from long term holders.

BTCcoinbeat.news
BTC/USD live chart
LIVEResearch by Galaxy Digital indicates that a security vulnerability in Coldcard hardware wallets has led to the theft of roughly 1,815 Bitcoin. The issue stems from a March 2021 firmware update that included a flawed random number generator. This error caused wallet keys to be generated with insufficient security, making them predictable to attackers who knew how to exploit the weakness.
Alex Thorn, head of research at Galaxy Digital, has been tracking the incident on the blockchain. He identified four distinct waves of attacks targeting over 5,000 addresses. Beyond these waves, Thorn also noted 14 additional patterns of theft that remain under investigation. The victims are largely long term holders whose coins had been sitting untouched for years before the attackers drained them.
Coinkite, the maker of Coldcard, has accepted full accountability for the bug and has released a firmware update to patch the issue. However, the company warns that the fix does not secure seeds created on the older, vulnerable firmware. If you use a single signature Coldcard wallet, you should move your funds to a new address immediately to prevent further loss.
For those who suspect their wallets may have been targeted, there is a narrow window of hope. If a victim spots an unauthorized transaction still waiting to be confirmed in the mempool, they may be able to outbid the attacker by paying a higher fee to move the funds to a secure wallet first. Victims are encouraged to file reports with the FBI and preserve their devices as evidence.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



