If you are a user of bitcoin, you are likely familiar with Coldcard, a hardware wallet dedicated to bitcoin that has recently fallen victim to a data breach.
According to Galaxy Research, hackers managed to siphon off over $100 million US worth of bitcoin from Coldcard hardware wallets.
Here is an overview of the ongoing hack, its impact on users, and steps to safeguard your cryptocurrency.
Functionality of Coldcard
Developed by Coinkite, a company based in Toronto, Coldcard is a hardware wallet that does not store bitcoin on your behalf.
While bitcoin remains on the public blockchain network, Coldcard enhances security by storing “seed phrases” offline within the physical device, ensuring they are never exposed to the internet.
These “seed phrases” are a series of random words that serve as a secure key to the bitcoin-only wallet.

These seed phrases act as digital signatures, enabling users to authorize and sign transactions as bitcoin owners.
Promoted as “cold storage” for long-term bitcoin holders seeking to keep their keys offline, Coldcard has been highly praised by users and security experts as one of the most secure places for storing bitcoin.
Incident Overview
Coinkite alerted its users on Thursday to a software bug permitting hackers to reconstruct wallet seed phrases.
This critical software vulnerability led to multiple attacks where hackers gained access to users’ bitcoin wallets without physical possession of the device.
As per Galaxy Research’s on-chain analysis, three confirmed attack waves and several smaller incidents resulted in the theft of 1,596 bitcoin from about 7,300 addresses by Monday.
If a fourth wave is confirmed, the total loss could escalate to around 2,055 bitcoin, valued at approximately $130 million US.
The perpetrators of the attacks remain unidentified.
-
Federal government plans to ban crypto ATMs to stop scammers from defrauding Canadians
-
Waterboarding, sexual assault, disguises: Details of terrifying $2M B.C. bitcoin hostage-taking revealed
Rodolfo Novak, Coinkite’s co-founder and CEO, advised Coldcard wallet users who generated a seed to “move your funds now” after releasing firmware updates for affected products.
In a post on X, Novak expressed, “We know an apology doesn’t return anyone’s funds. We know we’ll have to earn back our users’ trust.”
CBC News attempted to contact Coinkite but received no immediate response.
In a Sunday update, Coinkite acknowledged that the exploited flaw originated in March 2021, where affected firmware relied on a deterministic pseudo-random generator instead of the intended


