Coldcard Hack Exposes Bitcoin Wallet Vulnerabilities
Critical vulnerability in Coldcard hardware wallets has resulted in over $115 million in Bitcoin theft.

The Update
A firmware vulnerability in Coldcard hardware wallets has allowed hackers to steal over $115 million in Bitcoin, according to Galaxy Research. The bug, present since March 2021, caused seed generation to use a weak software random number generator instead of the hardware version, making seed phrases guessable. Galaxy Research has spoken with over 200 victims and estimates at least 15 separate attackers exploited the bug independently. The thefts have slowed since August 6, though total losses could exceed $130 million.
Why It Matters
This breach undermines trust in hardware wallets, which are considered the gold standard for Bitcoin security. The incident highlights risks in the self-custody model and may accelerate institutional adoption of custodial solutions. The stolen Bitcoin largely remains unmoved, suggesting attackers may be holding funds for future disposal or ransom. Coinkite acknowledged the bug “silently went unnoticed” and “its potential impact grew with every release” of its products.
What to Watch
Will Coinkite release a permanent fix for the vulnerability? How will the Bitcoin community respond to this security challenge? Will other hardware wallet brands reveal similar vulnerabilities? What regulatory response might this incident trigger? Are stolen funds potentially recoverable? Galaxy Research continues to monitor the situation and update its findings.
Sources
- bitcoinmagazine.com — confirming $115 million loss figure and details about the vulnerability
- decrypt.co — additional context on the attack methodology and Galaxy Research's findings



