If you use bitcoin, you may know about Coldcard, a bitcoin-specific hardware wallet that has recently been hit by a data breach.
According to Galaxy Research, hackers have managed to steal over $100 million US worth of bitcoin from Coldcard hard wallets.
Here’s the latest information on the ongoing hack, its impact, and steps you can take to safeguard your cryptocurrency.
Functionality of Coldcard
Coldcard, developed by Coinkite based in Toronto, is a hardware wallet that does not store your bitcoin. Instead, it enhances security by keeping “seed phrases” offline within the device, never needing connection to the internet.
The “seed phrases” are random words serving as a master key for the bitcoin-only wallet, enabling users to authorize and sign transactions securely.

Coldcard is marketed as “cold storage” for long-term bitcoin holders aiming to keep their keys offline, and it has been hailed by users and security experts as one of the most secure options for bitcoin storage.
Incident Details
On Thursday, Coinkite alerted its users about a software bug enabling hackers to reconstruct wallet “seed phrases.”
This critical vulnerability allowed multiple attacks, resulting in the theft of 1,596 bitcoin from around 7,300 addresses, with a potential total loss of 2,055 bitcoin valued at about $130 million US if a fourth wave is confirmed.
The identity of the attackers remains unknown.
Coinkite’s co-founder and CEO, Rodolfo Novak, advised users who have generated a seed using Coldcard to transfer their funds immediately after releasing firmware updates for affected products.
Novak mentioned that they are aware an apology cannot recover lost funds and acknowledged the need to rebuild users’ trust.
CBC News attempted to contact Coinkite for a response but received no immediate reply.
In a subsequent update, Coinkite acknowledged the software flaw originating in March 2021 and took steps to address it, emphasizing the importance of installing the latest firmware update.
Novak also cautioned other developers about potential vulnerabilities in firmware due to advancements in AI technology.
User Impact
All Coldcard users are at risk due to this software flaw, with about 90% of the stolen bitcoin remaining dormant in the same wallets since the theft.
Galaxy Research noted that the stolen funds have not been moved, sold, or exchanged, suggesting that hackers may be biding their time before transferring the funds.
Information from the investigation has been shared with U.S. law enforcement agencies, exchanges, and cyber-investigation groups.
Aneirin Flynn, CEO of FailSafe, highlighted the misconception of crypto being offline, noting that if the underlying encryption is compromised, passwords could be exposed.
Recommended Actions
If you suspect your wallet is compromised, do not leave your bitcoin in it. Install Coldcard’s latest firmware to secure newly created wallets post-update, while considering replacing vulnerable seed phrases generated on affected devices.
Coinkite advises customers to update their devices and refrain from generating new seeds until the update is installed.
Coinkite is conducting an investigation, and a detailed technical review will be released soon, although some experts believe the damage has already been done.
Affected users have the option to move their funds to a different custodian or exchange for safekeeping.
Galaxy Research suggested migrating funds to a secure address or generating a fresh seed if using Coldcard and uncertain about its safety.
Coinkite advised against discarding affected devices, as they may be crucial for potential fund recovery efforts.
