Coldcard Flaw Exposes $130M in Bitcoin via Seed Reconstruction
A critical vulnerability in Coinkite's hardware wallets allowed attackers to reverse-engineer seed phrases and drain funds remotely.
A critical software vulnerability in Coldcard hardware wallets has allowed attackers to reconstruct seed phrases and drain funds without physical access to the devices. The breach undermines the core security premise of "cold storage," proving that mathematical flaws in seed generation can render physical isolation irrelevant.
Produced by Toronto-based Coinkite, the wallets suffered from a flaw where a deterministic pseudo-random generator was used instead of a hardware-backed true random number generator in firmware dating back to March 2021. This vulnerability allowed hackers to reverse-engineer passwords and access funds remotely. Blockchain analysis confirms that approximately 1,596 bitcoin were stolen from roughly 7,300 addresses across three confirmed attack waves. If a suspected fourth wave is verified, total losses could climb to 2,055 bitcoin, valued at roughly $130 million US. Notably, roughly 90 per cent of the stolen bitcoin has not yet moved from the wallets where they were sent after the theft.
The Failure of Cold Storage
Coldcard is marketed as a high-security solution designed to keep seed phrases entirely offline to prevent remote attacks. However, this incident highlights a systemic risk: the device is only as secure as the math used to generate its keys. The attack exposes the fallacy of assuming crypto is safe simply because it is offline; if the underlying math is broken, passwords can be reverse-engineered regardless of the device's physical state.
Industry Implications and Market Volatility
This breach occurs during a period of significant market volatility, with bitcoin prices peaking above $126,000 in October before dipping below $65,000 in late July and early August 2026. Beyond the immediate financial loss, the event signals a shift in the threat landscape. The ability to identify such latent bugs at speed allows attackers to find vulnerabilities in open-source firmware faster than they can be patched, outpacing even the industry’s most seasoned experts.
The Path Forward
Coinkite is now tasked with recovering its reputation after the massive loss of user funds. The company has acknowledged that an apology does not return funds and that it must work to earn back user trust. While the three primary attack waves are confirmed, the industry is watching to see if the suspected fourth wave is verified, which would further increase the total amount of compromised assets.