Users of one of the most popular types of Bitcoin cold wallets were subjected to a massive cyberattack after hackers discovered a software vulnerability in Coldcard devices, which have long been considered one of the safest ways to keep cryptocurrencies off the internet.

Late last week, Coinkite, the Canadian developer of Coldcard devices, informed its users of a security vulnerability in the keys that protect Bitcoins, confirming that some wallets have become vulnerable to hacking due to this problem.

By Monday, the attackers had managed to steal more than 1,755 bitcoins, worth approximately $110 million, after draining the balances of nearly 5,000 wallets, according to data from Galaxy Research.

Coldcard is one of the most popular cold wallets, physical devices that allow users to store Bitcoin in an offline environment, which has made it ranked for years as the safest option for protecting digital assets from cyberattacks.

How did cold wallets become a weakness?

According to a report from Block Inc.'s engineering team, the problem stems from a flaw in the software responsible for creating what is known as a recovery phrase or seed phrase, which is a long string of words used to restore access to a digital wallet.

The report explained that these statements were not generated as randomly as they should have been, but were predictable as a result of a malfunction in the random number generation mechanism within Coldcard devices.

Anerin Flynn, CEO of cybersecurity firm Failsafe, said the incident reveals that the idea that cryptocurrencies remain safe simply because they are offline is not always true.

He added that the device is only responsible for generating the user's passwords, and if the mathematical algorithm that generates them is faulty, it is possible to rebuild those passwords and easily access the wallets.

Users shocked and losses within minutes

For many users, the news was initially hard to believe, as many thought their wallets would not be affected by the vulnerability.

Among the victims, Jonathan Goodman said he did not think the attack would target him, but decided to check his wallet as a precaution.

He added that as soon as he opened the wallet, he realized that everything was over, after he saw successive withdrawals appearing in red.

He explained that his three governorates were completely drained in just 7 minutes, between 9:36 and 9:43 pm on July 29.

The real reason behind the hack

The Block report indicated that the root of the problem lies in the method Coinkite used to generate the random numbers needed to create the recovery statements.

True randomness is a key element in modern encryption systems, but Coldcard devices in some cases relied on a backup mechanism that generated keys using predictable, fixed values, such as the device's serial number.

This allowed the attackers to systematically recalculate access keys, then access wallets and withdraw their entire contents.

Initial estimates on Friday suggested losses of nearly $38 million, but the value of the stolen currency rose rapidly over the weekend to over $110 million.

Company response and growing concerns

In an official statement on its website, Coinkite acknowledged that funds in wallets created using affected versions of the software are at risk.

The company confirmed that it has released new firmware updates for all affected devices and versions, urging users to install the updated versions as soon as possible.

The attack sparked widespread reaction within the cryptocurrency community, with influencers, cybersecurity experts, and company executives discussing the implications of the breach and whether it will affect trust in cold wallets in the future.

The breaches are decreasing... but the losses remain enormous.

Despite the magnitude of the attack, the total amount of money stolen from the cryptocurrency sector during 2026 is still less than last year.

According to a report released by TRM Labs last month, the value of cryptocurrencies stolen during the first half of the year was approximately $972 million, less than half the value of thefts recorded during the same period in 2025, which amounted to $2.3 billion.

However, the report noted that the number of hacking incidents had risen to 207 attacks, the highest number recorded during any 6-month period.

Ari Redboard, head of global policy at TRM Labs, explained that attacks related to infrastructure or private key compromise represent only about 15% of all incidents, but are responsible for 76% of all losses.

He added that the Coldcard incident proves that self-holding of cryptocurrencies does not eliminate risks, but rather transfers them to the user himself.

A crisis of confidence in the future of self-storage

As for the victim, Jonathan Goodman, the attack marked a turning point in his view of cryptocurrencies.

He said the incident made him realize how much blind trust he had placed in the technology he used, and stressed that he does not intend to invest in Bitcoin or use cold wallets again.

He added that the complexity of these systems and the difficulty in understanding how they work may make investing in them not worth the risk for many users, concluding: If it is this complicated, it may not be worth the effort... After all, no one really knows how these systems work.