The cryptocurrency world faced a nightmare scenario last week as hackers discovered a firmware flaw in Coldcard devices that allowed them to drain thousands of long-term Bitcoin wallets.
The exploit allowed them ot reconstruct the passwords protecting at least 1,367 hardware wallets. The hackers made off with an estimated $116 million.
Coldcard wallets are the brainchild of the Canadian firm Coinkite. Unlike “hot,” internet-connected wallets, Coinkite sells “cold” physical devices that look much like hard disk drives.
“I felt physically sick reading about the exploit before I checked my wallet on August 1,” one Coldcard user told Techopedia. The user, who spoke on condition of anonymity, said that “luckily” he was not among those affected.
On the r/Bitcoin subreddit, one user said that they were “considering divorce” with their partner after losing eight BTC, currently worth over $500,000.
Firmware Flaw Allowed Reconstruction of Wallet Seed Phrases
Using the exploit allowed attackers to reconstruct wallet seed phrases, the sequences of 12 to 24 random words that serve as master keys for crypto wallets.
Hacks are nothing new in the crypto space. But the Coldcard incident was unique, a rival crypto wallet provider explained.
“There was no phishing link. No malware, no leaked seed phrase. No one clicked anything,” the firm wrote. “The attackers simply computed the private keys. Because the keys were never truly random in the first place.”
The firmware flaw had caused several Coldcard wallet devices to use predictable software-based pseudorandom number generators to create seed phrases, instead of more sophisticated solutions.
“That reduced what should have been an astronomically large keyspace into something attackers could potentially search offline and validate against public Bitcoin addresses,” Joshua Copeland, the Director of Cybersecurity at Crescendo AI and a professor at Tulane University, told Techopedia.
The flaw was baked into the system around five years ago, lying dormant until hackers realized they could use it to force their way into the wallets.
Cold Wallet Security in Question Following Attack
The scary part about the exploit is the fact that Coldcard users were doing what Bitcoin experts have been urging everyone to do for years.
For as long as anyone can remember, experts have been telling anyone who owns crypto to keep it offline, in self-custody or so-called cold wallets.
Hackers, after all, have previously made off with billions of dollars’ worth of crypto in heists. Their chief target has usually been crypto exchanges and their web-connected hot wallets.
“Many exchanges came online as IT startups, with small teams and minimal security spending,” Gina Kim, a South Korean cybersecurity expert, told Techopedia. “Hackers saw their security infrastructure and multitasking staff as low-hanging fruit.”
Not so anymore. Binance says it spends hundreds of millions of dollars a year on security solutions, with its staff recovering over $60 million worth of cash and coins “linked to external hacks and security incidents” in the first half of 2026.
But Kim said hackers continue to take aim at larger exchanges. “More security spending and better training won’t deter most hackers,” she said. “They will still try their chances, because the potential rewards are so large.”
Hackers have already made off with $1.3 billion worth of crypto this year, per blockchain analysts. Last year, in one of the biggest hacks in crypto history, attackers stole $1.5 billion from the exchange Bybit.
The US government has blamed North Korea. Pyongyang consistently denies that it operates any state-sponsored crypto hacking units.
Improvements Expected Following Coldcard Attack, Says Expert
The question, however, remains. Is the Coldcard incident a one-off, or are cold wallets now compromised?
“A cold wallet is a security control, not a security guarantee,” said Copeland. “Not being connected to the internet is an important defense. But it does not compensate for defective key generation.”
“Cold wallets are still fundamentally better than other options out there,” Varun Choudhary, the co-founder and CEO of the blockchain firm ORO, told Techopedia. “Technically minded people can definitely go a step further to set up multi-signature wallets [wallets with more than one private key]. But for most normal people, sticking with top-tier hardware wallets should work.”
Choudhary added that the exploit would likely “harden the entire ecosystem,” as other providers scramble to ensure they do not fall victim to the same firmware flaw.
Also in Crypto News
AI Computing Now ’10 Times More Profitable’ than Mining Bitcoin
Data center owners have done the math. And it’s bad news for anyone who mines crypto.
ASIC miners, the rigs used by most commercial Bitcoin miners, are currently earning their operators up to $0.14 per hour, said Frank Holmes, the CEO of the Canadian BTC miner HIVE Digital Technologies.
Even an older graphics processing unit (GPU) generates ten times that amount when it is applied to AI computing.
Meanwhile, a single Nvidia H100 GPU can generate nearly $2 per hour, Holmes explained, per Wu Blockchain.
Many large crypto miners have already made the switch from Bitcoin to AI. The likes of Riot Platforms, MARA, Cipher Digital, and TeraWulf have all recently either diverted their efforts to AI computing or are now combining the two disciplines.
Rising costs and falling Bitcoin prices mean that most industrial miners now risk financial losses on each BTC they earn.
Eric Trump’s Bitcoin Mining Firm Posts $57.2M Losses
The misery for Bitcoin miners does not end with the above. American Bitcoin, the mining company co-founded by US President Donald Trump’s son Eric, has recently reported net losses of $57.2 million in the second quarter.
Its share price is also in the dumps, down almost 94% in the past 12 months. But despite the gloom, crypto winter appears to be skewing the numbers.
The firm holds much of its assets in the form of Bitcoin, meaning most of the losses are due to the quarter-to-quarter fall in Bitcoin prices.
Bitcoin prices are down by around 13% in the past quarter, after dropping over 21% in Q1.
In the past quarter, the miner has boosted the size of its Bitcoin holdings by over 14%, making it the world’s 16th-largest corporate Bitcoin holder, according to Bitcoin Treasuries data.
But a longer crypto winter could spell trouble for Eric Trump’s firm. Almost 40% of American Bitcoin’s BTC is being held as collateral under agreements with the company’s mining equipment partner Bitmain.
The company also handed over an 80% stake in its shares to the Florida-based mining firm Hut 8 when it launched in March last year.
Crypto Exchange Bitget Announces End of Japanese Services
Japanese regulators have forced the exchange Bitget out of the country’s crypto market.
“After careful consideration of compliance and related regulations in Japan, we have decided to terminate our services to residents of Japan,” the firm’s Japanese arm said in an X post.
The company said it has begun a “phased program of account restrictions.”
Japanese law dictates that only firms with government-issued operating permits can offer their services to Japan-based crypto traders.
This law is hard to enforce in the age of decentralized finance. But Japan’s financial regulator, the Financial Services Agency, is giving it a go.
The agency went on the warpath in November 2024, issuing a warning to Bitget.
The FSA objected to the fact that Bitget operates Japanese-language customer service platforms and lets users with Japanese addresses register as new account holders.
It sent similarly worded letters to KuCoin, MEXC Global, and Bybit.
Bybit responded by announcing a phased account restriction drive of its own late last year.
The FSA’s tight grip on the Japanese crypto sector has previously forced international operators like Coinbase to shutter their Tokyo-based operations.
