Coldcard Wallet Hackers Strike for Over $115M
A high-profile attack on Coldcard wallets has resulted in losses exceeding $115 million, making it one of the most significant hardware wallet security incidents in recent crypto history.
The vulnerability in question affects certain Coinkite devices and allows attackers to reconstruct seed phrases that were generated on affected hardware under vulnerable firmware conditions. This can lead to theft without the user's knowledge or consent, as an attacker can use the reconstructed seed phrase to access the wallet's private keys.
The attack began around July 30, 2026, and has continued with multiple waves of theft being confirmed. Researchers have identified over $115 million in losses, but estimates suggest that total losses could reach $130 million as more victims are discovered.