A security flaw in a popular Bitcoin hardware wallet has reportedly enabled the theft of more than $144 million across roughly 7,300 wallets, with researchers saying the attacks are ongoing.
The cryptocurrency heist affects Coldcard – a small, physical device which stores private Bitcoin keys offline and signs Bitcoin transactions without the keys touching the internet.
Though designed expressly for security and sovereign ownership, hackers have reportedly exploited a security-breaking vulnerability in the device to siphon more than 1,596 Bitcoin across a reported 7,300 Coldcard wallets.
Researchers at financial services company Galaxy Digital noticed the initial theft which took place across a 41-minute window on 30 July.
Since then, further attacks have surfaced and the amount of stolen Bitcoin has reportedly ballooned from an expected $98 million to the equivalent of roughly $144 million.
“The attack is ONGOING,” wrote Galaxy researchers.
Coinkite, the Canada-based maker of Coldcard, told Information Age it was “deeply sorry for the concern, disruption, and uncertainty” the situation has caused its users.
“We understand the responsibility that comes with building security products, and we regret putting our customers through this,” Coinkite said.
Coinkite chief executive Rodolfo Novak issued his own public apology on social media platform X.
“I'm sorry and I'm devastated,” said Novak.
“Our team is heartbroken.”
Novak noted the company does not store customer information and urged people to tell all Coldcard owners they know about the incident.
How are the hackers doing this?
In an early advisory published by Jack Dorsey's fintech company Block, engineering and security experts identified the root-cause vulnerabilities which allowed the Bitcoin to be stolen.
Block detailed a misconfiguration in Coldcard devices that resulted in them skipping their own hardware randomness generator, which is an essential component of the secure key generation needed to protect access to one’s cryptocurrency.
Rather than using Coldcard’s sophisticated randomness feature as intended, impacted devices fell back to a more deterministic, software-based random number generator.
Since the outputs of this feature could be inferred, attackers have been able to siphon funds without needing physical access to the victim’s Coldcard.
Notably, Block detected this vulnerability had appeared on affected devices as early as March 2021.
Coldcard users need to take action
Bitcoin security experts at WizardSardine explained there is a saving grace for some Coldcard users: if none of a user's key was generated via a Coldcard itself, they’re safe.
Though a fix has been rolled out, WizardSardine said those who are impacted will still need to repair their affected ‘seed’.
“A firmware update on its own changes nothing for the coins you hold today,” WizardSardine wrote.
“If any of your key was generated on a Coldcard or coming from a mnemonic initially generated on a Coldcard, you may be at risk.
“Thousands of Bitcoins have already been drained, and this is only the beginning.”
Coldcard has explicitly destroyed its remaining, unshipped inventory that was manufactured with the vulnerable firmware, though it has told users to keep their affected devices for potential use in recovering lost funds.
In the meantime, Coinkite’s chief executive has urged those affected to urgently move their funds elsewhere.
Bulk of funds funnelled to four addresses
According to a breakdown published by the research arm of Galaxy Digital, the funds from the initial 41-minute heist are, at the time of writing, sitting in four blockchain addresses.
This batch of pilfered Bitcoin represented approximately $98 million, or about 1,082 coins.
“[The] proceeds [were] consolidated within minutes and have NOT moved since,” Galaxy researchers explained.
“The pattern tells us these were all the same attacker.”
The transactions appeared to have been broadcast in coordinated “batches”, while victims mostly appeared to be individuals rather than institutions or cryptocurrency exchanges.

Galaxy charted the losses, which appeared to mostly impact individuals holding. Source: Galaxy Research
The company noted the theft window preceded Coinkite’s public security advisory for the exploit by roughly 30 hours.
Wallets still being drained
As of Tuesday, Galaxy staff have reported the thefts are ongoing after they uncovered a second and third “wave” of suspected Coldcard hacks, and three additional blockchain addresses related to the thefts.
Alex Thorn, head of firmwide research at Galaxy, said he was investigating a potential fourth wave of organised attacks linked to the vulnerability, while Galaxy has identified “14 smaller incidents” that could be related to attackers now picking up the known exploit.
Though Thorn has not received any direct victim reports to confirm this fourth batch of attacks, he has observed at least 709 victim addresses that appeared to be impacted.
At the time of writing, damages from this potential batch of attacks had reached at least 448 Bitcoin, valued roughly at $40 million.
If this batch of attacks becomes confirmed, the total damages from the collective attacks would be roughly $181 million or 2,000 Bitcoin.
Coldcard has confirmed it is “working directly with customers” and “walking through recovery options together”.
The company is expected to publish a full technical postmortem at a later date.
“The last three days have been some of the hardest in this company's history, and for a lot of the people reading this, they've been something much worse,” wrote Coldcard.
“Money that took years to save, gone.
“There are real lessons here for us as a company.
“We owe the community better, and we’re beginning to understand the many ways in which our best efforts and designs could have allowed for this to happen.”