If you’re a user of bitcoin, you might be familiar with Coldcard, a hardware wallet exclusively for bitcoin that has recently been targeted in a data breach.
According to Galaxy Research, hackers have siphoned off over $100 million US worth of bitcoin from Coldcard hardware wallets.
Here’s an overview of the ongoing breach, its impact, and steps you can take to protect your cryptocurrency.
How Coldcard Functions
Coldcard, developed by Coinkite based in Toronto, is a hardware wallet that does not hold your bitcoin. Instead, it enhances security by storing “seed phrases” offline within the physical device, never needing an internet connection.
“Seed phrases” are random word sequences, serving as a master key for the bitcoin-only wallet and enabling users to authorize and sign transactions.

Coldcard is marketed as “cold storage” for long-term bitcoin holders seeking to keep their keys offline, highly acclaimed by users and security experts for being one of the most secure ways to store bitcoin.
Incident Overview
Last Thursday, Coinkite alerted users to a software bug allowing hackers to reconstruct wallet “seed phrases,” leading to successive attacks on users’ bitcoin wallets without physical access to the device.
As per Galaxy Research, there have been three confirmed attack waves and several smaller incidents resulting in 1,596 bitcoin stolen from approximately 7,300 addresses, with a potential loss of 2,055 bitcoin valued at around $130 million US if a fourth wave is confirmed.
The attackers’ identities remain unknown.
-
Federal government plans to ban crypto ATMs to stop scammers from defrauding Canadians
-
Waterboarding, sexual assault, disguises: Details of terrifying $2M B.C. bitcoin hostage-taking revealed
Rodolfo Novak, Coinkite’s co-founder and CEO, recommended users who have generated a seed with a Coldcard to “move your funds now” after issuing firmware updates for affected products.
Novak stated, “We understand an apology won’t recover anyone’s funds. We know we need to regain the trust of our users.”
CBC News attempted to contact Coinkite without an immediate response.
In an update, Coinkite acknowledged the exploited flaw originating in March 2021, where vulnerable firmware used a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator.
Novak cautioned fellow developers, attributing the issue to AI’s role.
“To all developers: this reflects the reality of the new AI paradigm. AI-enabled code review can uncover latent bugs faster than seasoned industry experts. If your firmware is open-source or has been public, assume attackers and defenders are already scrutinizing it.”
