Over $100 Million in Bitcoin Stolen From Investors in Coldcard Wallet Hack – Here’s What Went Wrong

Over $100 Million in Bitcoin Stolen From Investors in Coldcard Wallet Hack – Here’s What Went Wrong

Image Credit: Associated Press

Key Points

  • Hackers reportedly stole an estimated $116 million in bitcoin from Coldcard hardware wallets, which had long been considered among the safest storage options.
  • A 2021 software update quietly weakened the wallets’ password randomness, significantly reducing their security.
  • The flaw went undetected for five years, while users who generated their own random passwords—often using physical dice—appear to have avoided the vulnerability.

Hackers have drained an estimated 1,800 bitcoin (BTC), worth roughly $116 million, over the past week from Coldcard hardware wallets in a breach that has rocked the crypto industry, according to data from Galaxy Research.

Bitcoin’s price dropped by around $2,000 in the three days following the first wave of hacks on July 30, as investor confidence was shaken, but has since recovered.

The CoinMarketCap Crypto Fear and Greed Index sits at 39 out of 100 as of August 6, indicating fear in the market. A hawkish Federal Reserve and August’s lousy track record for crypto share some of the blame here. But the timing is hard to miss.

Coldcard Exploit: How It Happened

As the first reports of drained wallets surfaced, financial-technology company Block’s (XYZ) bitcoin engineering and security teams went looking for the cause.

Working alongside independent researchers who have stayed anonymous, they pulled apart the firmware and traced the losses to the broken random-number password generator.

They later disclosed what they found to Coldcard manufacturer Coinkite and published the full technical breakdown publicly within hours.

Coinkite issued a preliminary advisory the same day and confirmed the five-year scope of the flaw on August 3.

The most surprising part of this stolen-bitcoin story? The victims were the careful ones.

A hardware wallet is a small physical device, about the size of a key fob, that stores the secret code protecting your bitcoin. People buy them precisely to keep their money out of banks, off exchanges, and away from the Internet. It’s supposed to be one of the safest storage options in the entire asset class.

Unfortunately, in this particular hack, these wallets were exactly the type of bitcoin storage that was breached.

In other words, the victims weren’t people who left their coins in an account on an exchange and hoped they were safe. These were careful investors who kept their crypto in one of the most secure and private wallets on the market – the bitcoin-only, air-gapped Coldcard wallet.

But for years, these investors had unknowingly been taking a big risk.

That’s because protecting bitcoin relies on “randomness” – using random numbers, which hackers can’t easily guess, to secure your account. It’s the same reason you would avoid using 1234 as your personal identification number (“PIN”).

The Coldcard wallet was supposed to generate a random number so strong (specifically, 128 bits) that it was like using a 38-digit number as your PIN. (“Bits” are used to measure the security strength of a crypto wallet’s private key or seed phrase. A higher number, such as 128, means the wallet is harder for hackers to break into.)

However, a 2021 software update reduced the Coldcard wallet security to as low as 40 bits, or more like a 13-digit PIN. It doesn’t take Stephen Hawking to see the difference.

This change in security protocol for wallet protection – that 40-bit random number – made hacking users’ bitcoin much easier.

Unfortunately, wallet users had no way of knowing this vulnerability existed. Auditors missed it, and the exploit sat quietly for five years before hackers began using it to breach Coldcard wallets.

Wallet holders who supplied their own randomness when generating their protective code appear to be unaffected by the breach.

Many of them used ordinary dice – like the kind we play games with – to determine a set of random numbers to protect their bitcoin.

What Is the Safest Way to Store Bitcoin Right Now?

Stephen Wooldridge II, an analyst for Stansberry Research’s Crypto Capital newsletter, puts it plainly: “Self-custody gives you full control over your funds, but good security practices are what let you keep them.”

There’s no single safest way to store bitcoin. Each option comes with trade-offs, so it’s important to pick one carefully… especially when just one BTC currently trades for north of $60,000.

There’s no perfect place to keep bitcoin. Here are the main options, and the trade-off each one asks you to accept.

  • Invest in a bitcoin exchange-traded fund (“ETF”), like BlackRock’s iShares Bitcoin Fund (IBIT), eliminates key risk – the risk you accept when you hold your own private keys (what failed for Coldcard) – and hands you counterparty risk instead. That is, you’re trusting BlackRock, the other party, to secure the investment. Some investors may not like that.

However, investing in an ETF removes any ability to move the asset off-chain, and it only trades during market hours versus bitcoin, which trades 24/7. Plus, if you’re attracted to bitcoin as an asset nobody can freeze… holding shares of an ETF gives that up.

  • Keep your bitcoin on an exchange, such as Coinbase, Kraken, Gemini, or Crypto.com, or in a brokerage account, such as Fidelity Digital Assets, which will maintain custody of your assets. They maintain the highest level of security possible, but like with ETFs you are still subject to counterparty risks.
  • Dice-generated paper wallets (where you write down your wallet address and private key) get you the strongest randomness if you want to create your own key or seed phrase. But they come with the weakest security… as a simple house fire is now your enemy.
  • Hardware wallets, such as Ledger or Trezor, can be loaded with randomness you supply yourself, but they rely on you to do the work. Having several keys held across different manufacturers in different locations can help mitigate your potential loss.

Think of securing your bitcoin like having millions of dollars in a bank account and finding out only a small portion of the total balance is insured by the Federal Deposit Insurance Corporation.

As a result, you might make deposits in multiple banks to maximize your protection. That’s what spreading your private keys across multiple devices can offer… the added security of spreading your risk so one compromised wallet can’t become a total loss.

Why the Coldcard Hack Isn’t a Bitcoin Problem

The uncomfortable part of this breach: Bitcoin worked as designed in this situation.

Nobody broke the protocol… The network saw valid transactions and signatures and did precisely what it was built to do: settle them without appeal. Immutability doesn’t take your side. It takes the side of whoever holds the key.

A vendor’s build script failed. The ledger didn’t.

Here’s what should really unsettle you: Every security system you rely on rests on parts you aren’t permitted to inspect. But still, you trust those… because you have no way of checking them yourself.

Your bank’s software, for instance, is closed to the public. When a bank does get breached (and they do!), you get a press release and a year of free credit monitoring… rather than a thorough explanation of how their systems were compromised.

Coldcard’s code, however, was public.

That’s not what caught the bug, of course. It sat in plain view for five years, and a paid outside security review missed it.

But once the coins started moving, independent researchers traced the root cause and published the full autopsy within a day, while the theft was still in progress. From that, the bitcoin industry immediately started working to improve security.

What Bitcoin Investors Are Doing Now

Many small bitcoin holders have already started moving their funds to increase their security.

Bitcoin-tracking sites report coins flowed back onto exchanges at a pace not seen in years after news of the hacks became public.

Now, you wouldn’t be faulted if, even after hearing about the hack, you didn’t want to send your bitcoin to an exchange and turn your asset into somebody’s receipt.

But you need more than conviction. It’s essential to ensure your bitcoin is held safely in a wallet built with proper random-number generation. Using ordinary dice makes sense if you want absolute randomness.

Think of it like this: If losing your bitcoin would majorly impact your financial life, the weekend it takes to build a real security setup isn’t an unreasonable cost.

Good investing,

Eric Wade

Editor’s Note: Whitney Tilson — the hedge fund manager CNBC called “The Prophet” — says America has reached its Ripping Point.” The old financial order is being torn apart, and he believes most investors have no idea what’s coming in the next six months. He’s named the stocks he thinks will be destroyed in the chaos — and the ones he believes will soar. Watch his free presentation while it’s still available. 

Big Tech Earnings: The AI Boom’s Biggest Winners and Losers
August 6, 2026

Big Tech Earnings: The AI Boom’s Biggest Winners and Losers

SpaceX Earnings Show Stock Overvalued by 3x
August 5, 2026

SpaceX Earnings Show Stock Overvalued by 3x

Is the Fed About to Pop the AI Debt Bubble?
August 5, 2026

Is the Fed About to Pop the AI Debt Bubble?

Recent Articles