For individuals using bitcoin, Coldcard, a bitcoin-exclusive hardware wallet, has recently fallen victim to a data breach resulting in the theft of over $100 million US worth of bitcoin from Coldcard hard wallets, as reported by Galaxy Research, a blockchain intelligence firm.
The ongoing hack has impacted numerous users, prompting concerns about securing their cryptocurrency assets. Here’s the essential information regarding the breach, its effects on users, and recommended security measures.
Functionality of Coldcard
Coldcard, designed by Coinkite, a Toronto-based company, operates as a hardware wallet that does not store bitcoin directly. Instead, it enhances security by storing “seed phrases” offline within the physical device, preventing online exposure.
The “seed phrases” function as a secure master key for the bitcoin-only wallet, allowing users to authorize transactions and manage their bitcoin holdings securely.

Coldcard is promoted as a “cold storage” solution for long-term bitcoin holders seeking to safeguard their keys offline and has earned accolades from users and security experts for its robust security features.
Incident Overview
Coinkite issued a warning on Thursday regarding a software bug that enabled hackers to reconstruct wallet “seed phrases,” leading to a series of attacks on users’ bitcoin wallets without physical access to the device.
Galaxy Research’s on-chain analysis revealed three confirmed attack waves and several smaller incidents, resulting in the theft of 1,596 bitcoin from approximately 7,300 addresses. If a fourth wave is confirmed, the total loss could reach 2,055 bitcoin valued at around $130 million US.
The perpetrators behind the attacks remain unidentified.
Impact on Users
All Coldcard users face the risk of their wallets being compromised due to the software vulnerability. Most of the stolen bitcoin remains untouched, indicating that the tokens have not been transferred, sold, or exchanged after the theft.
Details from the investigation, including attacker and victim addresses, have been shared with law enforcement agencies, cryptocurrency exchanges, and cyber-investigation groups to track and report any emerging threats.
Recommended Actions
Users are advised to transfer their funds from potentially compromised wallets and install Coldcard’s latest firmware, which secures wallets created post-update. Existing seed phrases generated on vulnerable devices should be replaced to mitigate risks.
Coinkite urges customers to update their devices promptly and refrain from generating new seeds until the fix is applied to prevent further vulnerabilities.
Although the investigation is ongoing, experts emphasize the importance of taking immediate actions to address the security breach and protect assets.
For affected users, migrating funds to a secure address at a custodian/exchange or generating a fresh seed is recommended to ensure asset safety. Coinkite advises against discarding affected devices, as they may be crucial for potential fund recovery efforts.
