Hackers Stole $70 Million in Bitcoin in Under an Hour by Exploiting a Single Software Flaw

0
9
Tima Miroshnichenko/Pexels

Bitcoin holders have increasingly turned to hardware wallets to keep digital assets offline and away from exchange hacks, making software integrity inside those devices a central part of crypto security. That broader risk came into focus on July 30, when researchers linked a fast-moving wave of thefts to a flaw in Coldcard wallet software made by Canadian company Coinkite. The incident has since become one of the most closely watched hardware-wallet security failures of the year.

More than 1,000 bitcoin drained in minutes

Security researchers at Galaxy Research said attackers drained more than 1,000 bitcoin from 1,196 wallets in just 41 minutes on July 30, a loss valued at roughly $70 million at the time. Forbes first reported the wave of attacks, and later reporting citing Galaxy’s blockchain analysis said two additional suspected waves pushed estimated losses to nearly $89 million. Galaxy also said its findings were based on blockchain data and that it had not confirmed every affected wallet had been created with the vulnerable software.

The wallets at the center of the warning were Coldcard devices, a line of bitcoin-only hardware wallets designed to store private keys offline. Coinkite confirmed in a security advisory that affected users should not rely on a routine software update alone if their recovery phrase was created on vulnerable firmware. The company said users need to generate a completely new seed and move funds to a newly secured wallet.

Coinkite CEO Rodolfo Novak also issued a public apology, saying the company was taking full accountability for the firmware bug and urging users to move funds immediately. In its advisory, the company stated that updating firmware does not repair an already generated seed. That distinction has become a key detail in the response because the weakness is tied to the recovery phrase itself rather than only to the device currently holding it.

The thefts were reported as a global incident, and no official public breakdown has identified how many affected wallet owners are in the United States. Coinkite has not released a state-by-state or city-by-city list of impacted customers, and researchers have not publicly tied the losses to a specific U.S. region. What is confirmed is that the warning has spread quickly across the U.S. crypto industry because Coldcard is widely used by self-custody bitcoin investors, including many who specifically avoid keeping assets on trading platforms.

Block’s Bitcoin Engineering and Security team said the coding mistake may have made some recovery phrases predictable enough for sophisticated attackers to reconstruct under certain conditions. Block also said none of its own products or customers were affected by this vulnerability, even though its researchers helped publicize the issue. That clarification narrowed the problem to Coldcard-generated seeds rather than the broader hardware-wallet market.

What remains unknown is the full number of U.S. users exposed, how many had already migrated funds before the thefts, and whether any losses have been reported to local or federal law enforcement in public case counts. Coinkite said it is cooperating with blockchain investigators and law enforcement agencies and would assist affected customers seeking police reports or insurance documentation. As of the latest public statements, the company said it was still working to determine the full scope of the breach.

According to Block’s advisory, the issue stemmed from a coding mistake that weakened a core security function involved in seed generation. Researchers said that flaw may have reduced the unpredictability of some recovery phrases, creating a path for attackers to derive wallet credentials remotely without physically touching the device. In a product category built around the promise of offline protection, that kind of failure is especially significant because seed randomness is the foundation of wallet security.

Coinkite has since released updated firmware intended to prevent newly created wallets from being affected in the same way. The company also said users who generated recovery phrases using at least 50 private dice rolls are not affected by this specific flaw alone, though it still recommended that uncertain users create a new seed and migrate funds. That advice reflects a broader principle in self-custody security: once a seed phrase may be predictable, the only durable fix is replacement.

For customers and residents in the U.S., the practical takeaway is narrower than the broader panic around crypto hacks. Users who created a Coldcard seed on affected firmware may need to move funds to a new wallet setup, while people using other products have not been included in this advisory. Coinkite said it plans to publish a fuller technical explanation after its investigation is complete, while researchers have said attacks may still be ongoing as the industry continues to assess the damage.

LEAVE A REPLY

Please enter your comment!
Please enter your name here