Hackers exploit flaw in ‘cold’ Bitcoin wallets, stealing $86 million
Hackers have exploited a software vulnerability in Coldcard hardware wallets, one of the most secure methods for storing cryptocurrency, stealing nearly $86 million worth of Bitcoin in an ongoing attack.
Tehran (ISNA) – Canada-based Coinkite informed users of its Coldcard devices late last week that a security flaw in the keys protecting their digital assets had compromised some wallets. According to Galaxy Research, by Monday, nearly 1,367 Bitcoin valued at approximately $86 million had been drained from more than 4,500 wallets.
Coldcard is a brand of hardware wallet designed to keep Bitcoin in so-called cold storage, which is supposed to be the safest way to hold digital currency because the devices are kept offline. However, according to Block’s engineering team, a software flaw in Coldcard devices made the generated recovery phrase — a long string of words used to access the wallet — predictable.
Ainirin Flynn, executive director of cybersecurity firm Failsafe, said: “This dispels the false belief that your digital currency is offline. The device is only responsible for generating your passwords, and if the underlying mathematical calculations are flawed, those passwords can be reverse-engineered.”
According to Block, the core issue was how Coinkite implemented the random number generator when generating the recovery phrases. True randomness is a critical component of cryptographic security, but Coldcard wallets had a backup mechanism that could lead to key generation using deterministic values such as the device’s serial number.
As a result, attackers were able to systematically recalculate and drain user wallets. Reports on July 31 estimated losses at about $38 million, but those figures grew rapidly over the weekend.
Coinkite confirmed in a statement that funds controlled by seeds generated on affected firmware are at risk, adding that a patched firmware is now available.
Cryptocurrency theft has declined in 2026 compared to 2025, with total losses reaching $972 million in the first half of the year — less than half of the $2.3 billion stolen in the same period last year. However, the total number of hacks rose to 207, the highest recorded in any six-month period.