Brivv
Coldcard Wallet Bug Blamed for $100 Million Bitcoin Theft Across Thousands of Users
CryptoНовость4 мин чтенияИИ-ассистент

Coldcard Wallet Bug Blamed for $100 Million Bitcoin Theft Across Thousands of Users

A flaw in how Coldcard hardware wallets generated seed phrases has been linked to the theft of over $100 million in bitcoin from thousands of users, according

17 августа 2026 г.Источник: coindesk.com

A vulnerability in how Coldcard hardware wallets generated seed phrases has been linked to the theft of more than $100 million in bitcoin from thousands of users, according to Galaxy Research.

Toronto entrepreneur Jonathan Goodman said his Coldcard wallet, which had never been connected to the internet and was stored in a safe deposit box, was emptied on July 29. He reported losing 18.25 bitcoin, worth just over $1.17 million at the time of the attack. "Perhaps the hardest part about this is that I did everything right," he wrote in an Aug. 1 X post.

Goodman's loss was part of a broader hack affecting thousands of Coldcard users. Galaxy Research said it had high confidence that 1,596 bitcoin — worth over $100 million — had been stolen from about 7,300 addresses in a series of attacks. Galaxy research head Alex Thorn estimated on Aug. 4 that at least 15 different attackers were exploiting the flaw. None of them needed physical access to a device.

Where the Flaw Originated

A hardware wallet's core security premise is that its secrets never leave the chip, making physical access the only way in. But in Coldcard's case, the vulnerability was not in the wallet device itself — it was in how the secret password, or seed phrase, protecting users' coins was generated.

Bitcoin wallets come in different forms. Software wallets, or "hot wallets," run on internet-connected devices, making them easy to use but exposed if the device is compromised. Hardware wallets, or "cold wallets," such as Coldcard, keep keys on a separate device not connected to the internet. Earlier forms of cold wallets, known as "paper wallets," involved writing down keys by hand — safe from hackers but at risk of being lost or damaged.

"Air-gapped systems help, but they are not a perfect fix," Bobby Gray, founder of TEXITcoin, told CoinDesk. "Security has to begin with how the keys are generated and continue through every part of the custody process."

  • Coinkite, the Toronto-based maker of Coldcard, sunset its hosted hot wallet in March 2016 amid junk traffic attacks, legal costs and regulatory complications.
  • The company pivoted to decentralized hardware, launching Opendime in April 2016, a USB stick that generated and concealed a private key.
  • Coldcard followed in December 2017, announced under the headline "The World Needs An Open, Cheap & Ultrasecure Hardware Wallet."

Read the full report at CoinDesk.

Читайте Brivv в Telegram

Главные новости финтеха и крипто первыми — с кратким разбором, почему это важно.

Подписаться@brivv_com_ru

Похожие статьи