Hackers Hit Bitcoin’s Safest Hiding Place in Ongoing Attack
Researchers said the flaw reduced seed entropy to as little as 40 bits and let attackers drain more than $88 million without touching the devices.
- On July 30, 2026, attackers exploited a Coldcard firmware vulnerability to drain roughly 1,367 Bitcoin worth about $86 million from over 4,500 addresses across multiple waves, according to Galaxy Research.
- A March 1, 2021 firmware commit caused Coldcard devices to bypass their hardware random number generator, forcing them to rely on predictable software-based randomness instead, drastically reducing seed entropy.
- Block's security team identified a coding error in a supporting library that checked only whether a setting existed rather than whether it was enabled, allowing the flaw to persist undetected in open code for over four years.
- Coinkite released emergency firmware on July 31, but the company warned that updating does not secure existing seeds; users must generate entirely new seeds on patched devices and migrate funds.
- The incident reignited debates over self-custody risks, with Bitcoin security company Casa CEO Nick Neuman urging users to spread funds across multiple wallets to mitigate single-point-of-failure vulnerabilities.
149 Articles
149 Articles
What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin
A Toronto-based company that made Coldcard, a bitcoin-only hardware wallet that has been the latest target of a data breach, has reportedly lost $100 million US worth of bitcoin as a result of the hack.
Watch Hackers Hit Bitcoin’s Safest Hiding Place
Bloomberg's Lauren Tara LaCapra joins Scarlet Fu and Tim Stenovec on "Bloomberg Crypto." Hackers have absconded with more than $100 million worth of Bitcoin from thousands of supposedly secure accounts in recent days, setting up another scandal for investors who have been repeatedly preyed upon by thieves in the sector.
New hacker raid: US$116 million stolen from Coldcard Wallets. Already transferred 1,816 bitcoins from digital enclosures
Hackers steal over $130M by exploiting bug in offline hardware wallets
A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain-monitoring firms.
Why the Coldcard Hack Put Bitcoin Wallets at Risk in 2026
A firmware bug in Coldcard hardware wallets has allowed attackers to drain nearly $89 million in Bitcoin from more than 4,500 addresses, according to CoinDesk. The attack began with a 25-minute sweep on July 31, when approximately 594 BTC worth around $38 million was taken from roughly 500 wallets. Two further waves pushed the estimated loss to about 1,367 BTC, or nearly $89 million, by August 2. The vulnerability affected the way certain Coldca…
Coverage Details
Bias Distribution
- 45% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium

































