Major Security Flaw in Cold Bitcoin Wallets Exposes Millions

Lisa Chang
7 Min Read
An inflatable monkey holding a Bitcoin sits on display during the Bitcoin 2026 conference in Las Vegas, Nevada, US, on Tuesday, April 28, 2026. The event will examine the future of money as Bitcoin enters a new era of institutional adoption and regulatory clarity. Photographer: Ian Maule/Bloomberg

We store our most valuable possessions in the most secure places we can imagine. For decades, that has meant a bank vault or a home safe. In the digital age, for a growing number of people, that place has become a “cold” hardware wallet—a small, purpose-built device designed to keep cryptocurrency keys offline and, therefore, supposedly impervious to online hackers. The entire promise rests on a simple, powerful idea: complete isolation. But what happens when the vault’s lock itself is flawed?

That unsettling question is now at the center of a crisis rocking the crypto community. A critical vulnerability has been discovered in Coldcard, a popular brand of Bitcoin hardware wallet from Canada-based Coinkite Inc. The flaw wasn’t in the device’s physical casing or its air-gapped design. It was buried in the mathematical heart of the system: the algorithm responsible for generating the all-important “seed phrase,” the master password that controls a user’s entire fortune. As reported by Galaxy Research, this weakness has led to the draining of roughly 5,000 wallets, with losses skyrocketing from an initial $38 million last Friday to over $110 million by Monday.

The technical details, explained by Block Inc.’s engineering team, reveal a profound failure in a foundational principle of cryptography: randomness. To be secure, a seed phrase must be generated using a truly random process, creating a unique, unpredictable key. According to the analysis, affected Coldcard devices had a fallback mechanism in their firmware. If the primary random-number generator failed, it would default to using deterministic values—like the device’s own serial number—to create the seed. This turned what should have been a cryptographic fortress into a predictable puzzle. Attackers, understanding this flaw, could systematically reverse-engineer the keys and gain control of wallets that had never touched the internet.

“It exposes the fallacy of your crypto being offline,” Aneirin Flynn, CEO of cybersecurity firm Failsafe, told Bloomberg. “The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.” This distinction is crucial. The breach didn’t compromise the “cold” storage concept by connecting the device to the web; it invalidated the trust placed in the device’s core function before the coins ever reached their offline sanctuary.

The human impact of this abstract failure is starkly real. Jonathan Goodman, one of the victims, shared his experience online. He stored his Bitcoin using a Coldcard device kept in a safety deposit box, a setup he believed was the pinnacle of security. On the evening of July 29th, he checked his wallet after hearing rumors of the attack. “The moment it loaded I knew I was screwed because I saw red lines for withdrawals,” he said. “Between 9:36 and [9:43 p.m.] on July 29th, all three of my wallets were completely drained.” He lost $1.6 million.

Goodman’s story underscores a painful lesson for the industry. For years, the mantra of “self-custody”—taking control of your keys away from third-party exchanges—has been preached as the ultimate security goal. This incident complicates that narrative. As Ari Redbord, TRM Labs’ global head of policy, noted, infrastructure and key compromises like this one make up only about 15% of crypto hacks but account for a staggering 76% of the total value stolen. “Coldcard shows that self-custody moves the risk, it does not remove it,” Redbord concluded.

The broader context, from a TRM Labs report published last month, adds another layer. While the total value of crypto stolen in the first half of 2026 is down significantly from 2025, the total number of individual hacks has reached a record high. The landscape is shifting from fewer, massive exchange heists to more frequent, targeted attacks on infrastructure and individual holders. This Coldcard breach is a potent symbol of that new frontline.

In response, Coinkite has stated that fixed firmware is now available for every affected model and release track. The company’s website confirms that funds controlled by seeds generated on the compromised firmware remain at risk, urging users to update immediately and transfer funds to a new, secure seed. But for users like Jonathan Goodman, the trust is broken. “If it really is this complicated and technical, perhaps it’s not worth doing,” he reflected. “Nobody knows how basically anything works.”

His sentiment points to a critical challenge for cryptocurrency’s maturation. The technology demands a level of personal responsibility and technical understanding that far exceeds traditional finance. When a user follows all the best practices—buying a reputable hardware wallet, keeping it offline, storing it physically securely—and still loses everything due to an invisible software flaw, it shakes the very foundation of user confidence. This breach isn’t just about $110 million in Bitcoin; it’s about the integrity of the tools upon which an entire financial paradigm is being built. The vault door was closed, but the lock was picked before the treasure was ever inside.

  • Coldcard vulnerability discovered
  • Firmware flaw led to loss of $110 million
  • Randomness critical for seed phrase security
  • Trust in technology compromised
  • Users advised to update firmware
  • Criticisms of self-custody practices
Aspect Details
Company Coinkite Inc.
Device Coldcard
Initial Loss $38 million
Subsequent Loss Over $110 million
Number of Wallets Affected 5,000
New Firmware Availability Yes

Share This Article
Follow:
Lisa is a tech journalist based in San Francisco. A graduate of Stanford with a degree in Computer Science, Lisa began her career at a Silicon Valley startup before moving into journalism. She focuses on emerging technologies like AI, blockchain, and AR/VR, making them accessible to a broad audience.
Leave a Comment