Key highlights:

  • A fresh crypto hack saw $86 million worth of BTC stolen from Coldcard wallets
  • Over 1,300 BTC were drained from more than 4,500 wallets
  • A software flaw made wallet recovery phrases predictable instead of random

Hardware wallets are considered the safest way to protect digital assets. But a new attack has changed that narrative, showing that even offline storage is not as secure as crypto holders think.

Hackers exploited a software flaw in Coldcard hardware wallets, draining over 1,367 Bitcoin worth $86 million from over 4,500 wallets, according to Galaxy Research. The incident was shocking to many because these wallets were particularly designed to keep private keys offline.

The attack came to light late last week after Canadian hardware wallet maker Coinkite alerted customers that some Coldcard devices had a security flaw that could affect the recovery phrases used to secure funds.

Bitcoin hardware wallet flaw exposes thousands of users

The attack was centred on Coldcard, a hardware wallet used to store BTC offline. These "cold wallets" are normally considered one of the safest storage methods because they are not connected to the internet.

However, researchers said that some versions of the wallet were generating seed phrases in a predictable way.

A hardware wallet creates a random seed phrase using a hardware random-number generator. This feature is what makes it almost impossible for hackers to guess a wallet's private keys.

But investigators found an internal firmware setting that allowed certain Coldcard models to skip the hardware generator. This flaw uses very predictable data like the device's serial number and clock values to create a seed phrase, which reduced the number of possible phrases.

Attackers used this flaw and recreated seed phrases on their devices. They then generated the wallet addresses linked to those phrases and compared them with addresses on the public blockchain.

Galaxy Research said the stolen funds came from different address formats. This includes 1,183 native SegWit wallets, seven legacy wallets, and six even older address types. Researchers also warned that users have no way to know whether their wallet is vulnerable.

Victims discover funds missing as investigation continues

Many of the victims of this hack have reacted on their social media pages. BTC holder Jonathan Goodman told Bloomberg that he thought his wallets were safe until he opened the application.

"The moment it loaded I knew I was screwed because I saw red lines for withdrawals," he said. Between 9:36 p.m. and 9:43 p.m. on July 29, all three of his wallets were emptied.

Investigators added that the attacker likely used publicly available blockchain data with the generated recovery phrases to narrow down vulnerable wallets. 

Reports also suggest a data provider unknowingly provided routine lookup services that matched the attacker's activity. 

Coinkite confirmed that wallets created using the affected firmware are at risk. The company has since released updated firmware for all impacted models and urged customers to install the latest version as soon as possible.

Industry reacts as security concerns grow

Binance founder Changpeng Zhao (CZ) reminded users that no storage method is completely risk-free. "Even hardware wallets can have bugs," Zhao wrote on X.  He told investors that spreading funds in multiple wallets could be the way to go to avoid these incidents.

The hack comes at a time when crypto theft is spiraling. In the first half of 2026, total crypto losses hit about $972 million. 

This is still lower than the $2.3 billion stolen in the first half of 2025. Ethereum and Solana suffered the most hacks that have happened so far.