Coldcard Wallet Vulnerability Drains Up to $89 Million in Bitcoin from Over 1,200 Addresses
Key Takeaways
- •A firmware coding error in Coldcard wallets may have made some recovery phrases predictable, potentially allowing attackers to steal Bitcoin without physical device access.
- •Galaxy Research reported that on July 30, attackers drained more than 1,000 Bitcoin from 1,196 wallets in 41 minutes, with total estimated losses reaching nearly $89 million.
- •Coinkite issued a firmware update but cautioned that users who already generated recovery phrases with affected software must create new seeds and migrate funds to be protected.
- •Coldcard CEO Rodolfo Novak publicly apologized, accepted full accountability, and urged all users who generated seeds on Coldcard devices to move their funds immediately.
- •Block's security team published its findings because it believes attacks are still ongoing, though the exact exploitation method remains under investigation.

A critical software flaw in Coldcard, a widely used Bitcoin hardware wallet, may have enabled attackers to steal approximately $70 million worth of Bitcoin in under an hour, prompting urgent warnings from security researchers and the device manufacturer.
Forbes first reported the attacks. Researchers at Galaxy Research say that on July 30, attackers drained more than 1,000 Bitcoin from 1,196 digital wallets in just 41 minutes. Galaxy subsequently identified two additional suspected waves of suspicious activity, raising estimated total losses to nearly $89 million.
Galaxy cautioned that its findings rely on blockchain analysis and that it has not confirmed every affected wallet was created using the vulnerable software.
Coldcard, manufactured by the Canadian company Coinkite, is a handheld device used by cryptocurrency investors to store Bitcoin offline rather than on a cryptocurrency exchange. Commonly referred to as a "hardware wallet," the device is designed to prevent hackers from accessing a user's Bitcoin remotely. Hardware wallets are widely recommended by security experts as one of the safest methods for storing cryptocurrency because they keep private keys disconnected from internet-connected devices, making this type of vulnerability particularly notable within the industry.
According to a security advisory from Block's Bitcoin Engineering and Security team, a coding error in certain versions of Coldcard's firmware may have weakened one of the wallet's key security features. Block said the bug could have made some recovery phrases predictable enough for sophisticated attackers to deduce them under specific circumstances, potentially allowing theft of Bitcoin without physical access to the device. A recovery phrase, also known as a seed phrase, is a sequence of words that functions as a master key, granting full access to the funds stored in a wallet. If compromised, an attacker can control the associated Bitcoin regardless of which physical device or software is used.
Block stated it released its findings because it believes the attacks are still ongoing, though researchers noted they are continuing to investigate exactly how the vulnerability is being exploited.
Coinkite has since issued a software update designed to prevent the issue from affecting newly created wallets. However, the company warned that simply installing the update will not protect users who already generated a recovery phrase using the affected firmware.
"Updating the firmware does not repair a seed that was generated by affected firmware," Coinkite said in its security advisory. "A new seed must be generated and the funds migrated to the new wallet."
Coinkite also cautioned that importing the same recovery phrase into a different wallet does not resolve the vulnerability, because the weakness is tied to the recovery phrase itself rather than the physical device.
Coinkite CEO Rodolfo Novak issued a public apology on X, stating the company was "heartbroken" and accepting "full accountability for the firmware bug."
"I'm sorry and I'm devastated," Novak wrote. "Our team is heartbroken about yesterday's news."
Novak urged customers to take immediate action: "If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further."
He also appealed to the broader community to help disseminate the warning: "If you know anyone who owns a Coldcard, please make sure they see this. Some affected users may not be watching social media right now, and every hour matters."
Novak said Coinkite is still working to determine the full number of affected users and plans to publish a detailed technical explanation following its investigation. "We do not have full attribution or scope of the issue yet, and we won't speculate until our full technical evaluation is complete," he wrote.
The company said it is assisting affected customers who wish to file police reports or insurance claims and is cooperating with blockchain investigators and law enforcement agencies.
The warning spread rapidly across the cryptocurrency industry. Jan3 CEO Samson Mow wrote on X: "If you're using a COLDCARD, any version firmware or MK, migrate your funds immediately. If you know someone who is, let them know ASAP... Attacks are ongoing so do it quickly."
While the initial advisory focused on older Coldcard devices, Coinkite has since expanded the list of affected products to include additional models and software versions. The company noted that customers who generated their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone. Nevertheless, Coinkite recommends that anyone uncertain about how their wallet was configured create a new recovery phrase and migrate their funds as a precaution.
Block emphasized that none of its own products or customers are affected by the vulnerability. The company said it published its findings after collaborating with anonymous security researchers and receiving reports from Coldcard users.
Separately, developers of Jack Dorsey's Bitkey wallet said they are investigating a different reported issue involving their product but are not advising customers to stop using the wallet.
"Our recommendation is to continue to use your Bitkey normally," Bitkey developer Clay Garrett wrote on X. Garrett said the reported issue would require "exceptional circumstances" to exploit and would not provide an attacker with sufficient information to steal customer funds. "Our assessment is this presents no risk of remote drains or immediate funds loss," he added.
FOX Business reached out to Coinkite, Galaxy Research, Block, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Royal Canadian Mounted Police (RCMP), the Canadian Centre for Cyber Security, and Chainalysis for comment but did not immediately receive responses.