Skip to content

Bringing you global stories from a neutral view

Cryptocurrency

Coldcard Wallet Hack Drains Over $70 Million in Bitcoin

A firmware flaw in Coinkite's Coldcard hardware wallets let hackers brute-force seed phrases, draining tens of millions in bitcoin.

Coldcard Wallet Hack Drains Over $70 Million in Bitcoin

Coldcard hardware wallets made by the Canadian company Coinkite became the target of a wave of hacking attacks, with owners losing 1,082.65 bitcoin, worth more than $70.2 million, on the first day alone. Estimates of total losses vary from 1,778.84 BTC to 2,417.35 BTC, or between $115 million and $153 million.

The breach stemmed from a flaw in how the devices generated seed phrases, the strings of words used to restore access to a wallet. Seed phrases are supposed to be created entirely at random, but a firmware error meant that on some devices the phrase could be recovered through brute force, by systematically guessing possible combinations.

The cryptographic entropy of the seed generation, meant to measure 128 bits, was reduced to 72 bits on some devices and to as little as 40 bits on others. The fault lay with the source of randomness, which drew on predictable data such as time values from a software-based generator instead of the required hardware-based one, making private keys far easier to guess.

The vulnerability itself dates back to 2021, meaning attackers could theoretically have exploited it for five years before acting now. Coldcard's older Mk2 and Mk3 models were hit hardest.

To illustrate why entropy matters, some estimates suggest that 128 bits of randomness offers so many possible combinations that if every star in the observable universe stood for one possible answer, finding the right one would mean searching through all the stars in 340 trillion equivalent universes. Cutting entropy by just a few dozen bits reduces the number of combinations that must be tried by many orders of magnitude.

Coinkite released corrected firmware. Affected users were told to generate a new seed phrase, confirm the new wallet with a test transaction, and move any remaining bitcoin to it. Although the flaw affected Coldcard specifically, the episode dented confidence in hardware wallets generally.

Trezor and Ledger Respond

Trezor and Ledger, two of the best known makers of hardware wallets, both issued statements about the Coldcard situation, similar in substance but differing in detail.

Trezor said its devices were secure, though the company added a caveat: if a wallet had originally been created on a vulnerable Coldcard and its backup then imported or restored onto a Trezor device, that user's funds could still be at risk. Trezor said even its older Safe 3 and Safe 5 models were safe because they use random generation through the Optiga Secure Element chip, while the newer Safe 7 uses a TROPIC01 chip for the same purpose, both providing 128 bits of entropy.

Ledger's chief technology officer, Charles Guillemet, rejected any suggestion of a threat to his company's devices. He said all of Ledger's technical solutions use a True Random Number Generator, and that its Secure Element chip provides 256 bits of entropy for every 24-word phrase.

SafePal Data Leak

Earlier in August, a separate case caused a stir at SafePal. Between March of last year and April of this year, personal data belonging to almost 40,000 SafePal customers was exposed. Fortunately for those affected, the leak did not include anything tied specifically to cryptocurrency, such as seed phrases, private keys or digital assets. It did include names, physical addresses and contact details.

The problem was traced to a plugin used to track orders, through which attackers are believed to have gained access to the data. SafePal said it fixed the flaw and introduced additional security measures. Data held in its processing system will now be kept for only 90 days, the company said, and it shut down 30 websites and phishing links connected to the vulnerability.

Trezor Customer Data Breach

Trezor itself then disclosed a similar problem, saying hackers had breached its logistics partner, ShipMonk. The attack compromised personal data belonging to roughly 14,000 Trezor customers, in full or in part.

As with the ShipMonk breach, the main danger is not that wallets themselves became less secure, but that attackers obtained users' personal data, including names, home addresses, emails and phone numbers, which could be used to launch phishing attacks or even threaten victims directly. News of the Coldcard, SafePal and Trezor incidents emerged in close succession, reinforcing negative sentiment toward hardware wallets.

What a Hardware Wallet Actually Stores

A hardware wallet is not literally a place where bitcoin or other assets are held. All crypto assets exist only on the blockchain, and access depends on possession of a private key. A wallet, hardware or otherwise, is simply a way of interacting with the blockchain that stores that key.

Storing assets on hot wallets or exchanges carries its own risks from hacking and malware, and cold hardware storage, it turns out, is not immune either. The options for storing a seed phrase or a private key each carry drawbacks: a phrase written on paper can be damaged or lost, and memorizing it is highly unreliable. Metal plates that let users stamp or arrange letter tiles to record a seed phrase, sold by companies including Ledger, whose product is called Billfodl, and by smaller manufacturers, offer an alternative to paper.

Amid the Coldcard problems, the volume of transfers on the bitcoin network rose, with users moving savings to centralized exchanges, choosing custodial storage over control of their own funds. Ledger's chief people officer, Ian Rogers, pointed to a broader problem than any single hardware wallet: artificial intelligence. He said the Coldcard vulnerability had existed for five years but was only exploited in 2026, once attackers began using neural networks to breach its defenses. In his view, the issue lies not with hardware wallets themselves but with the fact that the growth of AI has significantly expanded the tools available to attackers.

Should You Abandon Cold Storage?

For most users, no alternative to hardware wallets currently matches their combination of security, simplicity and convenience. That does not make cold wallets flawless, but other options carry as many drawbacks, sometimes more, as shown by users who moved assets to exchanges rather than search for a safer way to hold their own keys. The advance of artificial intelligence cuts both ways, helping developers strengthen defenses even as it helps scammers find flaws more quickly.

Related

Leave a comment

Your email address will not be published. Required fields are marked *