Wednesday, August 12, 2026

“Data Breach Exposes Coldcard Users to $100M Bitcoin Theft”

Related

“Insect Populations Declining Globally, Scientists Warn”

Recollections of summer evenings filled with moths and mayflies...

Investor Consortium Offers Sherritt International Lifeline

A group of investors has stepped in to assist...

“Federal Budget Unveils 16,000 Job Cuts by 2029”

The recent federal budget announcement revealed plans to cut...

“WestJet Cabin Crew Union Reaches 18% Wage Increase Deal”

The union representing WestJet cabin crew has disclosed details...

“Duck Lake, SK, Offers Naming Rights for $10M”

A small town in Saskatchewan is on the hunt...

Share

If you’re a user of bitcoin, you might be familiar with Coldcard, a hardware wallet exclusively for bitcoin that has recently been targeted in a data breach.

According to Galaxy Research, hackers have siphoned off over $100 million US worth of bitcoin from Coldcard hardware wallets.

Here’s an overview of the ongoing breach, its impact, and steps you can take to protect your cryptocurrency.

How Coldcard Functions

Coldcard, developed by Coinkite based in Toronto, is a hardware wallet that does not hold your bitcoin. Instead, it enhances security by storing “seed phrases” offline within the physical device, never needing an internet connection.

“Seed phrases” are random word sequences, serving as a master key for the bitcoin-only wallet and enabling users to authorize and sign transactions.

Two types of Bitcoin wallets are displayed on a website.
Two different bitcoin-only hardware wallets showcased on Coldcard’s website, designed by Coinkite, a Toronto-based company. (Coldcard.com)

Coldcard is marketed as “cold storage” for long-term bitcoin holders seeking to keep their keys offline, highly acclaimed by users and security experts for being one of the most secure ways to store bitcoin.

Incident Overview

Last Thursday, Coinkite alerted users to a software bug allowing hackers to reconstruct wallet “seed phrases,” leading to successive attacks on users’ bitcoin wallets without physical access to the device.

As per Galaxy Research, there have been three confirmed attack waves and several smaller incidents resulting in 1,596 bitcoin stolen from approximately 7,300 addresses, with a potential loss of 2,055 bitcoin valued at around $130 million US if a fourth wave is confirmed.

The attackers’ identities remain unknown.

Rodolfo Novak, Coinkite’s co-founder and CEO, recommended users who have generated a seed with a Coldcard to “move your funds now” after issuing firmware updates for affected products.

Novak stated, “We understand an apology won’t recover anyone’s funds. We know we need to regain the trust of our users.”

CBC News attempted to contact Coinkite without an immediate response.

In an update, Coinkite acknowledged the exploited flaw originating in March 2021, where vulnerable firmware used a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator.

Novak cautioned fellow developers, attributing the issue to AI’s role.

“To all developers: this reflects the reality of the new AI paradigm. AI-enabled code review can uncover latent bugs faster than seasoned industry experts. If your firmware is open-source or has been public, assume attackers and defenders are already scrutinizing it.”

Impact on Users