Tuesday, September 8, 2026

“Coldcard Wallet Breach: $100M Bitcoin Stolen”

Date:

Reports have surfaced of a security breach targeting Coldcard, a bitcoin-only hardware wallet, resulting in hackers siphoning over $100 million US worth of bitcoin, as per blockchain intelligence firm Galaxy Research. The breach has affected numerous users, prompting concerns about securing cryptocurrency assets.

Coldcard, developed by Coinkite in Toronto, functions as a hardware wallet that does not store bitcoin but enhances security by offline storage of “seed phrases” within the physical device. These seed phrases, serving as master keys, authorize and sign transactions on the blockchain network. The wallet, known for its cold storage feature, is highly regarded by users and security experts for its secure bitcoin storage capabilities.

The breach stemmed from a software bug identified by Coinkite, allowing hackers to reconstruct wallet seed phrases and access users’ bitcoin wallets remotely. The breach led to the theft of 1,596 bitcoin from around 7,300 addresses, with potential losses escalating to 2,055 bitcoin worth roughly $130 million US if further attacks are confirmed.

Coinkite’s CEO, Rodolfo Novak, urged affected users to transfer their funds and issued firmware updates for impacted products. The company disclosed the flaw’s origin in March 2021 and cautioned developers about potential vulnerabilities, attributing the incident to AI advancements in bug detection.

All Coldcard users face risks due to the software bug, with approximately 90% of the stolen bitcoin stagnant in the same wallets. Investigations are ongoing, with details shared with law enforcement agencies, exchanges, and cyber-investigation entities. Experts emphasize the need to monitor blockchain activity for potential fund movements by hackers.

To mitigate risks, users are advised to update their wallets with the latest firmware, replace vulnerable seed phrases, and refrain from generating new seeds until the update is installed. Coinkite’s investigation continues, emphasizing proactive measures to address the breach. Affected users can consider transferring funds to secure addresses, custodians, or exchanges while retaining the affected device in case of fund recovery efforts.

Share post:

Popular

More like this
Related

“Canada-US Tariff Talks Deadlocked as Deadline Looms”

Canada and the United States are still facing significant...

“Spider-Man: Brand New Day” Shatters $500M Milestone

"Spider-Man: Brand New Day" swings into box office history...

“From Spectator to Fan: A Filipino Immigrant’s Love Affair with Canadian Hockey”

Growing up in the Philippines, I had never witnessed...

“Goodfood Market Corp. Granted Creditor Protection for Restructuring”

A request for creditor protection by Goodfood Market Corp....