What we know about ongoing Coldcard hack that’s stolen over $100M worth of
If you’re a bitcoin user, then you may be familiar with Coldcard — a bitcoin-only hardware wallet that has been the latest target of a data breach.
Hackers reportedly drained more than $100 million US worth of bitcoin from Coldcard hard wallets, according to blockchain intelligence firm Galaxy Research.
Here’s what we know about the ongoing hack, who is affected and what you should do to secure your cryptocurrency.
How Coldcard works
Coldcard, created by Toronto-based company Coinkite, is also known as a hardware wallet — but it doesn’t actually store any bitcoin for you.
Bitcoin remains on the public blockchain network, but a Coldcard adds an extra layer of security by storing “seed phrases” offline — without ever needing to be connected to the Internet — inside of the physical device.
“Seed phrases” are a sequence of random words, meant to be difficult or impossible to guess, which act as a master key to the bitcoin-only wallet.

The seed phrases, or keys, act as a digital signature that allow a user to authorize and sign transactions, as the owner of the bitcoin.
The wallet is marketed as “cold storage” for long-term bitcoin users who want to keep their keys offline and has been widely praised by users and security experts as one of the most secure places to store bitcoin.
What happened
On Thursday, Coinkite warned its users of a bug in the software that allowed hackers to reconstruct wallet “seed phrases.”
That major vulnerability in its software allowed waves of attacks where hackers were able to gain access to users’ bitcoin wallets, without ever needing to physically get ahold of the device.
As of Monday, an on-chain analysis by Galaxy Research said that three confirmed attack waves and a number of other “smaller incidents” have resulted in 1,596 bitcoin stolen from roughly 7,300 addresses, it said in a post on X.
If a suspected fourth wave is also verified, the total could jump to some 2,055 bitcoin lost, which is worth roughly $130 million US.
It’s unclear who is behind the attacks.
Rodolfo Novak, the co-founder and CEO of Coinkite, advised anyone who has generated a seed using a Coldcard wallet, to “move your funds now,” after releasing firmware updates for affected product, according to an advisory on its website.
“We know an apology doesn’t return anyone’s funds. We know we’ll have to earn back our users’ trust,” Novak said in a post on X on Friday.
CBC News has reached out to Coinkite but did not immediately hear back.
In an update on Sunday, Coinkite acknowledged that the exploited flaw originated in March 2021, where instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware had relied on a deterministic pseudo-random generator. The company said it destroyed remaining inventory manufactured with the vulnerable…
Read More: What we know about ongoing Coldcard hack that’s stolen over $100M worth of