Friday, September 11, 2026
HomeBusinessColdcard Data Breach: $100M Bitcoin Stolen

Coldcard Data Breach: $100M Bitcoin Stolen

Coldcard, a bitcoin-only hardware wallet, has recently fallen victim to a data breach resulting in over $100 million US worth of bitcoin being stolen. Created by Coinkite, Coldcard operates by storing “seed phrases” offline, providing an additional layer of security for bitcoin users. These seed phrases serve as a master key for the wallet, allowing users to authorize and sign transactions securely.

The breach was brought to light when Coinkite issued a warning to its users about a software bug that allowed hackers to reconstruct wallet seed phrases, enabling unauthorized access to users’ bitcoin wallets without physical possession of the device. As of the latest update, approximately 1,596 bitcoin from around 7,300 addresses have been stolen in confirmed attacks, with a potential total loss of 2,055 bitcoin valued at around $130 million US if further incidents are confirmed.

Coinkite has advised users to move their funds immediately and has released firmware updates for affected products. The company acknowledged that the vulnerability originated in March 2021 due to a flaw in the firmware’s random number generation process. Coinkite has destroyed remaining inventory with the vulnerable firmware and halted shipments upon confirming the issue.

All Coldcard users are at risk of potential wallet compromise due to the software bug. Although roughly 90% of the stolen bitcoin remains in the same wallets, experts warn that the funds could still be moved or exchanged. Investigations into the breach have been shared with law enforcement agencies, exchanges, and cyber-investigation groups to track and report attacker addresses.

To safeguard their assets, users are advised to install Coldcard’s new firmware, especially for wallets created after the fix. Existing seed phrases generated on vulnerable devices should be replaced to mitigate risks. Coinkite continues its investigation, and a technical review will be released soon. Affected users are encouraged to transfer their funds to secure addresses or seek assistance from custodians/exchanges. Coinkite urges users not to dispose of affected devices, as they may be needed for potential fund recovery efforts in collaboration with law enforcement.

RELATED ARTICLES

Most Popular