Skip to content
Back to Guavy Wire
Crypto

Coldcard Wallets Hit by $114 Million Hack

Instruments
BTC
Share

A major security vulnerability in Coldcard wallets led to over $114 million being stolen from more than 5,200 addresses. The issue, which started in March 2021, allowed attackers to recover offline keys by brute-forcing a limited range due to the use of a software pseudo-random number generator instead of a hardware one.

The first wave of attacks on July 30 took only 25 minutes and brought in 594 BTC. By August 2, three waves had emptied 4,585 addresses, and the next day researchers recorded a fourth. At least 15 independent attackers joined the scheme, with total losses potentially reaching $130 million.

CoinKite released an emergency firmware update for all affected models on August 4 and directly contacted owners to warn them about the risk.

The incident highlighted weaknesses in hardware wallets, particularly when it comes to seed phrase generation. Coldcard's strengths include its focus on Bitcoin, key isolation, hardware entropy generation, and additional security modes, but a high entry threshold may deter beginners from using the device properly.

More on Crypto

Disclaimer: Guavy is a data and market intelligence provider, not an investment advisor. The information, signals, and market analysis provided by the Guavy API and related services are for informational purposes only and are not intended as financial advice, investment recommendations, or an endorsement of any particular trading strategy. Trading in volatile markets, including cryptocurrency, carries significant risk and may not be suitable for all investors. Past performance is not indicative of future results. Users should consult with a qualified financial professional before making any investment decisions. Guavy makes no guarantee of trading profits or financial returns.

Market sentiment intelligence for apps, funds & agents

Location

729 55 Ave SW
Calgary AB T2V 0G4
Canada

© 2026 Guavy Inc