Coldcard Hack Leads to $114 Million in Bitcoin Theft

A security flaw in Coldcard's firmware has led to the theft of nearly $114 million in bitcoin from over 7,300 wallets. The vulnerability allowed attackers to exploit the seed generation process. This issue was identified on July 29, 2026. Galaxy Research reported that about 1,596 bitcoin was stolen, affecting around 709 addresses. The hack was executed quickly, with about 500 wallets emptied in just 25 minutes.

Firmware Flaw Details

The bug in Coldcard's code was due to a lack of randomness in the seed generation process. This problem lasted for more than five years in the open-source codebase. The flaw was introduced in March 2021 during a major rewrite of the firmware. This rewrite followed a licensing change that restricted competitors. Zach Herbert, CEO of Foundation, noted that the community relied on one person's judgment, which ultimately failed to protect users. He stated, "Don't trust, verify" only works when qualified people actually look, and for five years, effectively nobody did.

User Experiences

Among those affected, Toronto entrepreneur Jonathan Goodman reported losing 18.25 bitcoin, valued at over $1.17 million at the time of the attack. Goodman emphasized that he followed best practices for security. He kept his device offline and his seed phrase secure. The incident has raised concerns about the reliability of hardware wallets, which are marketed as secure against online threats. Users are now questioning the effectiveness of Coldcard's security measures and what this means for the broader cryptocurrency market. For further context, see the article on the Coldcard hack's impact.

Related coverage: Bitcoin Cold-Wallet Attack Hits 4,500 Addresses, $89M Lost.

Market Impact

The hack is likely to increase scrutiny on hardware wallet security. It could also lead to a decline in confidence among users, impacting the broader cryptocurrency market. Investors may reassess their reliance on hardware wallets as a secure storage option. Watch for further developments in security protocols from hardware wallet manufacturers in response to this incident.

Based on reporting by: coindesk.com

Share: