Bitcoin Vaults Cracked — Millions Vanish

Various cryptocurrency coins scattered around a smartphone displaying market data
BITCOIN VAULTS CRACKED

A flaw in Coldcard hardware wallets let attackers drain bitcoin from thousands of addresses, and the losses kept climbing as the scope widened.

Quick Take

  • Galaxy Research tied the opening wave to 1,082.65 BTC, worth about $70.2 million, taken from 1,196 addresses in 41 minutes.
  • Later reporting said the total rose to about 1,367 BTC, or nearly $89 million, across 4,585 addresses after two more waves.
  • Researchers and reporters traced the problem to a Coldcard seed-generation flaw that began with firmware changes in March 2021.
  • Coinkite warned users to update affected devices while investigators kept watching for more thefts.

How the Attack Unfolded

The first wave hit fast. On July 30, attackers swept bitcoin from 1,196 addresses in a 41-minute window, taking 1,082.65 BTC and leaving a clear on-chain trail for Galaxy Research to follow. That opening burst looked like a single coordinated event, but it turned out to be only the start.

Later analysis showed two more suspected waves, which pushed the total losses much higher and spread the damage across far more wallets.

By early August, the running total had reached about 1,367 BTC, or nearly $89 million, across 4,585 addresses. That scale made the incident one of the largest hardware-wallet thefts in recent memory.

Coindesk reported the third wave alone drained about 208 bitcoin from 1,912 addresses, showing that smaller balances were also being targeted. The pattern suggests a methodical campaign, not a one-time smash-and-grab.

Where the Weakness Came From

Multiple reports point to a flaw in how Coldcard generated wallet seeds, the starting material that protects a Bitcoin wallet. The bug reportedly dated to a March 2021 firmware change and could cause the device to fall back to weak, deterministic software random number generation instead of the hardware random number generator.

That matters because if the seed is predictable, the private key can be reproduced offline and the wallet can be emptied without touching the device.

Coinkite’s warning focused on affected firmware ranges and urged users to update as soon as possible. Reporting also said the problem may affect several Coldcard model lines, not just one version. That broader reach is what makes the episode unsettling.

A tool marketed for cold storage is supposed to be the last place a thief can reach, yet a seed flaw turned that promise into a trap for users who thought they had done everything right.

Why This Story Matters

This attack fits a familiar crypto pattern: one technical flaw, then a rapid wave of forensic reporting, then a bigger number as more wallets are linked to the same weakness. That is why the first loss estimate was not the final one. The important lesson is plain.

Hardware wallets are only as strong as the code that creates the keys inside them. If that code fails, the physical shell offers little comfort.

For bitcoin owners, the immediate question is whether their own seed was generated during the vulnerable period. For the wider market, the larger question is trust. People buy cold storage because they want fewer moving parts and fewer chances for human error.

This case shows that the weakest link can hide at the very beginning, long before anyone sends a coin, and that is the part many users never think to test.

Sources:

foxbusiness.com, thehackernews.com, cryptopolitan.com