Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

theblock+1theblock+1marketscreener+1A firmware vulnerability in Coldcard hardware wallets made by Toronto-based Coinkite has led to the theft of an estimated $130 million in Bitcoin from approximately 7,300 wallet addresses, marking one of the most damaging exploits ever to target self-custody infrastructure.
The attack, which began on July 30 with an initial drain of 594 BTC, has unfolded across multiple waves. The root cause is a 2021 firmware bug that generated wallet seeds using a weak software random number generator instead of the device's hardware entropy source, allowing attackers to brute-force wallet keys offline. Galaxy Digital research initially tracked 1,367 BTC stolen from 4,585 addresses by early August, with the total rising to at least 1,816 BTC across four theft waves as of last week.theblock+4
Coinkite released patched firmware and urged affected users to generate entirely new seeds and migrate funds. "Updating the firmware does not change or repair an existing seed," the company stated in its security advisory. Users who generated wallets on Mk3 firmware versions 4.0.1 through 4.1.9 without using at least 50 independent dice rolls are considered at risk.bitcoinmagazine+1
The fallout has driven a visible on-chain response. New Bitcoin addresses climbed from roughly 260,000 to more than 330,000 last week as affected users rushed to create fresh wallets and migrate funds, according to The Block.theblock
Alex Thorn, head of firmwide research at Galaxy Digital, said on Bloomberg Crypto that Bitcoin will "survive" the hack, noting the vulnerability was specific to Coldcard's key generation and not a flaw in the Bitcoin protocol itself. Becca Amilee Rubenfeld, COO and co-founder of AnchorWatch, described Bitcoin as "a canary in the coal mine" for AI-assisted hacking threats, pointing to a Chinese AI model released two weeks ago that may be connected to the exploit.bloomberg+2
The incident has reignited debate over the trade-offs of self-custody. As CoinDesk reported when the exploit first surfaced, the breach "suffered one of its biggest blows — maybe ever" to the promise that hardware wallets eliminate counterparty risk. The Block noted that while self-custody removes counterparty risk, "it doesn't remove implementation risk".coindesk+1
Money has since flowed into Bitcoin ETFs as some holders reassess their custody arrangements. It remains unclear who is behind the attacks.cbc+1