It remains unclear who is behind the hack. While recent large crypto thefts have often been attributed to state-backed groups in North Korea or Russia, investigators have not yet linked this incident to any specific actor.
Coldcard, made by Canadian technology firm Coinkite, is a small hardware device that keeps Bitcoin keys offline, marketed as “cold” storage for long‑term holders. That offline design was supposed to make it one of the safest places to park Bitcoin, but a flaw in Coldcard’s process created a fatal vulnerability.
The weakness is rooted in a 2021 Coldcard software update that changed the way the wallet generated its recovery phrase—a series of random words, such as “pepper” or “floorboard” for instance, that provide a means of regenerating the dozens of random characters that make up a Bitcoin address.
According to a report by the Bitcoin engineering and security teams at financial technology firm Block, the Coldcard devices stopped using strong, unpredictable randomness to generate phrases, and instead took a shortcut process that follows patterns. Once attackers learned that, they could mirror the same process on their own computers, guess many possible recovery phrases, and see which ones unlocked real wallets—letting them steal funds without ever touching the device.
Coinkite has since issued an open letter strongly advising users who generated a wallet seed on Coldcard devices to move their funds as soon as possible.
“The last three days have been some of the hardest in this company’s history, and for a lot of the people reading this, they’ve been something much worse,” the company said in a social media post.
The Coldcard attack is one of hundreds of crypto hacks this year. Over the past six months, attackers launched 207 separate incidents—the most ever recorded in any half‑year period by blockchain analytics platform TRM Labs. Yet total losses reached about $972 million, or less than half the $2.3 billion stolen in the first half of 2025.
Read more The Danube is running dry, and Europe’s power grid is suffering as a result
The breach rocked sentiment on Crypto Twitter, with influencers and company executives commenting on its implications. Despite this, the prices of Bitcoin and Ethereum were contained overall, with both cryptocurrencies experiencing less than a 1% drop since Thursday.
On July 30, mapping the flow of funds for the original Coldcard vulnerability identified by Block, Galaxy Research discovered that, in the span of just 41 minutes, 1,196 addresses were fully drained for a little over 1,083 Bitcoin, or approximately $70.2 million.
By the following day, additional reporting confirmed that a major portion of these early losses—roughly 594 Bitcoin worth $38 million—occurred in a single 25-minute sweep of about 500 single-signature wallets. The third wave of sweeps occurred between Friday midday and Saturday morning, draining 208 Bitcoin from 1,912 addresses. On Monday morning, investigators detected the fourth wave, which ultimately brought the total estimated losses to 1,816 Bitcoin.
The incident has reignited a long‑running debate among Bitcoin holders over where to keep their coins. While some still argue strongly for self‑custody, others say this hack has pushed them toward the perceived safety and simplicity of large centralized platforms like Binance and Coinbase.
Binance founder Changpeng Zhao, commonly known as CZ, raised the issue in a recent social media post. “I’m a believer in self-custody, but it puts the burden on you,” he said.