Business

Coldcard Flaw Triggers $116M Bitcoin Loss Across 5,200 Addresses

A software flaw in Coinkite hardware wallets allowed hackers to guess recovery phrases and drain over 5,200 addresses.

A fatal security flaw in Coldcard hardware wallets has enabled attackers to steal 1,816 Bitcoins worth approximately $116 million, forcing Canadian manufacturer Coinkite to issue an emergency warning instructing users to evacuate their funds immediately. The ongoing exploit has compromised more than 5,200 individual addresses across four distinct attack waves, exposing a rare vulnerability in hardware devices long considered the most secure storage method in the cryptocurrency industry.

According to findings from financial technology firm Block‘s engineering and security teams, the compromise traces back to a 2021 software update that degraded the randomness used to generate recovery seed phrases. Rather than producing cryptographically unpredictable word combinations, affected Coldcard devices began following deterministic patterns. Attackers identified these predictable sequences and used high-speed computing to replicate the seed generation process, unlocking target wallets and draining funds remotely without physical access to the devices.

On-chain tracking by blockchain intelligence firm Galaxy Research highlights the speed and coordination behind the theft. The initial breach on July 30 saw 1,196 addresses drained of 1,083 Bitcoins—valued at $70.2 million—in just 41 minutes, including a single 25-minute sweep that took 594 Bitcoins worth $38 million from roughly 500 single-signature wallets. Subsequent sweeps between Friday and Saturday morning siphoned another 208 Bitcoins from 1,912 addresses, before a fourth wave on Monday morning pushed total losses past 1,816 Bitcoins.

While the identity of the perpetrators remains unconfirmed, investigators have not linked the exploit to state-sponsored hacking groups in North Korea or Russia, which have historically driven major digital asset thefts. The attack occurs despite broader industry improvements in security; data from TRM Labs shows that while a record 207 exploit incidents occurred in the past six months, total global crypto losses stood at $972 million—less than half the $2.3 billion stolen during the first half of 2025.

Coinkite acknowledged the crisis in an open letter, describing the past several days as among the hardest in the company’s history. Despite the severity of the hardware compromise, broader market impact remained subdued, with both Bitcoin and Ethereum prices declining by less than 1% following the disclosure.

The breach has fundamentally shaken confidence in self-custody models, where holders retain sole responsibility for their private keys. Commenting on the shift in sentiment, Binance founder Changpeng Zhao noted that while self-custody offers sovereign control, it places full security burdens on individual holders. The event has prompted an influx of investors to evaluate shifting capital back toward centralized platforms like Coinbase and Binance.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button