S&P 500100.00-1.70%NASDAQ112.50-0.85%Apple125.000.00%Microsoft137.50+0.85%Google150.00+1.70%Amazon162.50-1.70%Tesla175.00-0.85%Meta187.500.00%Bitcoin200.00+0.85%Ethereum212.50+1.70%EUR/USD225.00-1.70%Gold237.50-0.85%Oil250.000.00%
The Wiregazette
Closeup of novelty one million dollar bills laid out in a fan arrangement.
Crypto

$140 Million Coldcard Hack Exposes Critical Flaw in Bitcoin Hardware Wallets, Shakes Self-Custody Faith

5 min de lecture

Partager

Hackers exploited a software bug in Coinkite Inc.’s Coldcard wallets to steal at least 1,600 bitcoin worth roughly $140 million, prompting a crisis of confidence in the security of offline crypto storage and a broader market reassessment of self-custody risks.

A massive security breach at Toronto-based crypto storage company Coinkite Inc. has resulted in the theft of at least 1,600 bitcoin — valued at approximately $140 million — from users of its Coldcard hardware wallets, according to research from New York-based digital asset firm Galaxy.

The hack, which unfolded over the past week, exploited a software bug that made the wallets’ seed phrases — the master keys used to access bitcoin — far less secure than intended. Instead of being randomly generated from a vast pool of possibilities, the bug made seeds predictable, allowing attackers to brute-force their way into users’ wallets without ever touching the physical devices.

“It’s like they told people that it was going to be a combination lock with 1 trillion numbers, but because of the bug, it just had a 1,000 numbers,” Henry Kim, an associate professor at York University, told the Financial Post.

The incident has sent shockwaves through the cryptocurrency community, which has long considered cold wallets — devices that store private keys offline — to be among the most trusted methods for securing digital assets. The breach undermines that foundational assumption.

“There is a lot of soul-searching and re-evaluating going on. The bug was just shockingly bad,” said Eric Chennells, a Vancouver-based cybersecurity analyst and cloud computing consultant, as reported by The Globe and Mail.

**Victims Hit in Minutes**

One victim, Toronto-based author and former personal trainer Jon Goodman, told The Globe and Mail that his Coldcard Mk3 wallets were emptied of more than 18 bitcoin — worth over $1.6 million — in just seven minutes on the evening of July 29. Goodman said he never shared his seed phrase and kept his devices disconnected from the internet, with his Coldcard wallet stored in a safety deposit box. He has filed police reports and a report with the Ontario Securities Commission.

“I think that there is a very legitimate chance that whoever is responsible for this will be caught and arrested,” Goodman told The Globe and Mail. “I think that there’s almost no chance that any of the funds are going to be recovered.”

The Financial Post reported that dozens of bitcoin investors around the world collectively lost millions after their Coinkite accounts were compromised.

**How the Bug Worked**

Coinkite was founded in 2012 and has supplied investors with offline hardware wallets, which it calls Coldcards, for years. Each device stores the private keys needed to access bitcoin on the blockchain. The vulnerability was in the part of the Coldcard wallet code used to create seed phrases, according to a blog post that Coinkite’s support team shared with Goodman. A coding error introduced in 2021 made seed phrases much easier to guess, according to the post.

Attackers could use the easily-guessed seed phrases to determine wallet keys and find ones containing bitcoin, without requiring access to hardware wallets, the blog post said.

**Coinkite Response**

In a blog post dated Sunday, Coinkite said it had been working directly with customers and “walking through recovery options together.” It said it had destroyed the remaining inventory of vulnerable Coldcard wallets and issued software patches to prevent the bug from affecting new seed generation.

“We also believe this vulnerability is a warning for every company building Bitcoin hardware and software, not only us,” Coinkite said in another post on Monday, as reported by The Globe and Mail. “We’re publishing this now, while the details are still fresh, because other companies need time to check their own code to prevent potential further loss.”

The company said recent artificial-intelligence-assisted reviews of the Coldcard software code did not catch the vulnerability.

Coinkite did not respond to The Globe and Mail’s questions on Tuesday.

**Market and Security Implications**

The hack comes amid a broader period of market uncertainty. Bitcoin traded at roughly $64,267 as of early evening on Aug. 4, up 0.9%, according to Nasdaq. Ethereum rose 0.5% to $1,874.13. The market sentiment improved from “Extreme Fear” to “Fear,” according to the Crypto Fear & Greed Index, as reported by Benzinga.

The Nasdaq noted that despite the ongoing Coldcard hack, crypto prices gained alongside major stock indexes on renewed optimism that the Strait of Hormuz may reopen soon, with oil prices falling.

Lifehacker reported that hackers have carried out more than 200 crypto attacks between January and July of this year, leading to losses of $972 million — an increase in the number of events, but a significantly lower amount stolen compared to the first six months of 2025.

**Protection and Diversification**

According to Coinkite’s security advisory, the vulnerability has now been patched for all affected firmware. Users should install available updates from official download pages and migrate their wallets to a new seed phrase following the instructions in the advisory, Lifehacker reported.

Chennells told The Globe and Mail that bitcoin holders concerned about security vulnerabilities could consider diversifying their exposure. “Hold some in ETFs, some in a smaller vault, some in mining or ecosystem companies,” he said. “People have to make individual choices based on their risk tolerances and knowledge and principles.”

The hack has also drawn attention from regulators. In a notice in February, the Canadian Investment Regulatory Organization noted that “historical failures in the crypto sector, including losses due to hacking, fraud, inadequate governance, and insolvency, have demonstrated that custody arrangements are a critical point of investor vulnerability,” The Globe and Mail reported.

The broader market context shows large holders are accumulating. CryptoQuant reported that Bitcoin whale holdings, excluding exchanges and mining pools, rose to about 3.06 million BTC from 2.87 million BTC in December 2025, with accumulation accelerating after Bitcoin dropped below $60,000 in June.

“Rising whale balances into price weakness is the clearest smart-money tell,” CryptoQuant said, as reported by Cointelegraph, adding that the accumulation pattern has historically preceded market bottoms while cautioning that the market remains exposed to further downside.

Partager

À propos de Howard Lim

Crypto & Digital Assets Reporter. Covers cryptocurrency markets, blockchain infrastructure, and the institutional adoption of digital assets. He reports on token prices, protocol developments, and regulatory pressure without cheerleading or dismissiveness. DeFi, exchange flows, and Bitcoin/Ether market structure are regular themes.

Articles connexes