Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

bloombergcryptocrypto+1Hackers have drained an estimated 1,596 to 1,816 bitcoin — worth between $100 million and $130 million — from more than 7,300 addresses tied to Coldcard hardware wallets in the largest hardware wallet exploit in crypto history. The attack, which began on July 30, exploited a five-year-old firmware flaw that weakened the randomness used to generate wallet seed phrases, allowing attackers to brute-force private keys without ever touching a physical device.crypto+2
Toronto-based Coinkite, the maker of Coldcard, declined to confirm specific loss figures in a statement to Bloomberg on Wednesday. "We're not in a position to independently confirm total losses or validate the specific figures being reported by third parties," the company said.bloomberg
The vulnerability traces to a March 2021 firmware update that introduced a build configuration error. A macro called MICROPY_HW_ENABLE_RNG, set to zero, caused a supporting cryptographic library to bypass the device's dedicated hardware random number generator and fall back to a predictable software substitute. The result: seed phrases on Mk3 devices were generated with roughly 40 bits of entropy instead of the intended 128 bits — reducing security from an effectively uncrackable lock to one a computer could brute-force in minutes.memeburn+1
Block's bitcoin security team published the full technical breakdown after tracing the flaw alongside anonymous independent researchers. Galaxy Research tracked four attack waves: the first on July 30 swept 1,082 BTC from 1,196 addresses in 41 minutes; subsequent waves through August 4 brought confirmed losses to 1,596 BTC, with a suspected fourth wave potentially pushing the total to 2,055 BTC.crypto+2
The breach's cruelest irony is that it struck bitcoin's most security-conscious holders. "Perhaps the hardest part about this is that I did everything right," Canadian entrepreneur Jonathan Goodman wrote on X after losing 18.25 BTC worth approximately C$1.6 million from a Coldcard stored in a safety deposit box. Tim Lamb, a 38-year-old marketer whose seed was stamped on a metal plate hidden inside a fake dictionary, lost two bitcoin worth around $130,000 while on vacation.news.bloomberglaw+1
Coinkite CEO Rodolfo Novak apologized on X on July 31, writing: "We know an apology doesn't return anyone's funds. We know we'll have to earn back our users' trust." The company issued emergency firmware, destroyed remaining vulnerable inventory, and halted shipments — but warned that patching does not repair seeds already generated on compromised firmware.crypto+2
The breach has reversed a two-year trend of bitcoin flowing off exchanges. CryptoQuant reported sub-1 BTC transfers hit 39,600 BTC on July 31, near the panic levels seen when FTX collapsed in 2022. Cantor Fitzgerald told clients the hack could steer demand toward managed custody providers and spot bitcoin ETFs such as BlackRock's iShares Bitcoin Trust, naming Coinbase and Robinhood among potential beneficiaries.thestreet+1
Roughly 90 percent of stolen funds remain unmoved at attacker-controlled addresses, though analysts have identified one actor beginning to route approximately 64 BTC through Wasabi Wallet's CoinJoin mixer. Galaxy Research has shared roughly 600 suspected attacker addresses with U.S. federal law enforcement and crypto exchanges.coinpaper+2