All Crypto Blogs

How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

coindesk.com · Aug 17, 2026 at 13:57

How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds
coindesk.com Aug 17, 2026

Jonathan Goodman followed the rules for keeping his bitcoin safe.

The hardware wallet holding his keys, a Coldcard, had never been connected to the internet. He kept it stored in a safe deposit box. The seed phrase, which he’d never shared with anyone, was stored in a second safe deposit box. But on July 29, Goodman said, every wallet he had was emptied, every last satoshi stolen. The Toronto entrepreneur reported losing 18.25 bitcoin, worth just over $1.17 million at the time of the attack.

“Perhaps the hardest part about this is that I did everything right,” he wrote in an Aug 1 X post.

Goodman’s loss was part of a much larger hack impacting thousands of Coldcard users. Galaxy Research said it had high confidence that 1,596 bitcoin — worth over $100 million — had been stolen from about 7,300 addresses in a series of attacks. Galaxy research head Alex Thorn estimated on Aug. 4 that at least 15 different attackers were exploiting the flaw. None of them needed physical access to a device.

A hardware wallet’s entire security premise is that its secrets never leave the chip. With no internet connection, there’s no way in beyond physical access to the device. Though the physicality of a hardware wallet carries its own risks for users — as banal as misplacing the device and as frightening as a wrench attack — their major selling point is that they are safe from hackers and other online bogeymen.

But, in the case of Coldcard, this security promise fell short. The vulnerability was not in the wallet itself — it was in how the secret password, or seed phrase, protecting users’ coins was generated.

Bitcoin wallets can come in different forms. Software wallets, also called “hot wallets,” run on an internet-connected device, making them easy to use but exposed if the device is compromised.

Hardware wallets, or “cold wallets,” such as Coldcard keep the keys on a separate device that’s not connected to the internet. One of the earliest forms of cold wallets were so-called “paper wallets,” where users wrote down the keys needed to access their wallets on a piece of paper. Though safe from hackers, these wallets carried an enormous risk of being damaged or lost.

Hardware wallets are somewhere in between a paper wallet and a browser-based hot wallet. They’re harder to hack than software, harder to lose than paper, but they’re not infallible. They can be lost or stolen, and users need to be able to trust the device to create their keys properly in the first place.

“Air-gapped systems help, but they are not a perfect fix,” Bobby Gray, founder of TEXITcoin, told CoinDesk. “Security has to begin with how the keys are generated and continue through every part of the custody process.”

This is, unfortunately, where things went wrong for Coinkite, the maker of the Coldcard wallet.

In March 2016, the Toronto-based bitcoin company told customers it was sunsetting its hosted hot wallet. Running an online financial services company had brought persistent floods of junk internet traffic aimed at knocking their services offline, along with mounting legal costs and regulatory complications.

Source

This article is syndicated for educational reading. For the latest updates, visit the original publisher.

Read on coindesk.com

Recently Used