Skip to main content
← Back to market wire
Market signalFox Business

Coldcard wallet attack drains up to $89M in Bitcoin from 1,200+ addresses

A Coldcard firmware bug may have let attackers steal roughly $70 million in bitcoin in under an hour, and the company says attacks are still ongoing. Estimated losses now at $89M.

Desk analysis

AI-assisted2 min read

A hardware wallet is supposed to be the last line of defense in cryptocurrency. Coldcard, a Canadian-made device marketed to serious bitcoin holders who want their assets offline and out of reach, just became the cautionary tale of the week. A firmware bug allowed attackers to drain roughly $70 million in bitcoin from 1,196 wallets in 41 minutes on July 30, with two additional waves pushing estimated losses to nearly $89 million.

The mechanics matter. The vulnerability did not require physical access to the device. A coding error in certain Coldcard firmware versions weakened the entropy of generated recovery phrases, making them predictable enough for sophisticated attackers to reconstruct under specific conditions. The seed phrase is the wallet. Once the seed is compromised, moving it to another device accomplishes nothing, because the weakness travels with the phrase itself.

Coinkite, the Toronto-based manufacturer, has released a patched firmware. The patch protects newly generated seeds. It does nothing for seeds already created on vulnerable versions. The only remediation is to generate a fresh seed on updated firmware and migrate funds. CEO Rodolfo Novak's public apology was unusually direct for the hardware wallet space, where vendors typically hedge. He told users to move funds before reading further and asked the public to help notify Coldcard owners who might not be watching crypto Twitter during a holiday weekend.

The incident exposes a structural problem in self-custody. Hardware wallets promise sovereignty by removing third-party custody risk. They introduce a different risk: firmware supply chain integrity. A single coding mistake in a small company's software can compromise thousands of devices that were specifically purchased to avoid exactly this kind of failure. The irony is precise.

Block's Bitcoin Engineering and Security team, which disclosed the flaw, was careful to note that its own products and customers are not affected. That distinction matters. Block operates Cash App and the Bitkey wallet, both of which compete in adjacent territory. The disclosure reads as responsible disclosure from a rival rather than a coordinated industry response.

For the broader market, the signal is straightforward. Hardware wallet users should treat their devices like any other software dependency: verify firmware versions, audit seed generation practices, and assume that any seed created under questionable conditions is permanently suspect. The $89 million figure is a reminder that the cost of a bad seed is not theoretical.