Hackers have stolen more than USD$100 million (CAD$140 million) worth of Bitcoin from thousands of supposedly secure cryptocurrency wallets after exploiting a software flaw in hardware devices made by Canada-based Coinkite Inc.
Coinkite warned customers late last week that some Coldcard devices had been compromised. Additionally, researchers estimated that hackers had already drained more than 1,755 Bitcoin worth about USD$110 million from roughly 5,000 wallets by Monday.
The breach affected Coldcard hardware wallets designed to store Bitcoin offline through so-called cold storage. However, a flaw in the wallet software allowed attackers to predict recovery credentials that users believed were securely randomized.
The theft triggered widespread concern across the cryptocurrency community. Victims reported watching their balances disappear within minutes despite using devices marketed as one of the safest storage options available.
Jonathan Goodman said he realized something was wrong as soon as he opened his wallet and saw a series of unauthorized withdrawals. He told Bloomberg News that attackers emptied all three of his wallets within seven minutes on July 29, costing him about USD$1.6 million.
According to cryptocurrency security experts, the problem originated in how the devices generated recovery phrases. These seed phrases consist of a series of words that allow owners to regain access to their wallets if they lose the original device.
Security researchers at Block Inc. (NYSE: XYZ) determined that the software sometimes failed to generate truly random seed phrases. Instead, the devices occasionally relied on predictable values, including serial numbers, when producing recovery credentials.
Read more: Malaysia crypto raid exposes Southeast Asia’s growing electricity theft problem
Read more: TeraWulf lands USD$19B Anthropic lease while selling Texas AI data centre stake
Self-custody only as secure as the methods used to protect private keys
Consequently, attackers could recreate those seed phrases by calculating the same values. They then gained access to affected wallets and transferred Bitcoin without needing the physical devices.
True randomness forms the foundation of modern cryptographic security because it prevents outsiders from predicting passwords or encryption keys. When that randomness fails, even sophisticated security systems become vulnerable to determined attackers.
Reports initially placed losses near USD$38 million on Friday. However, estimates climbed rapidly throughout the weekend as investigators identified additional compromised wallets.
The incident sparked intense discussion across social media platforms. Investors, cryptocurrency developers and industry executives debated how such a flaw could affect devices specifically designed to eliminate online security risks.
Ayesha Kiani, chief operating officer at digital asset investment firm Monarq Asset Management, said the incident showed that self-custody remains only as secure as the methods used to create and protect private keys.
Meanwhile, Coinkite acknowledged that some customer funds remained at risk. The company released updated software intended to address the vulnerability and help customers who had become locked out of their devices.
Cold wallets differ from online cryptocurrency wallets because they store private keys offline rather than on internet-connected systems. Many investors use them to reduce exposure to exchange hacks and malware attacks.
However, hardware alone cannot guarantee security. Every device still depends on software to generate the secret recovery phrase that controls access to digital assets.
“It exposes the fallacy of your crypto being offline,” said Aneirin Flynn, chief executive officer of cybersecurity technology firm Failsafe.
“The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered.”
Read more: Galaxy launches USD$5M Bitcoin quantum readiness initiative
Read more: Core Scientific lands USD$14B AMD AI infrastructure partnership
Number of successful attacks increases despite total lower losses
If that process produces predictable results, attackers can recreate the same credentials without physically possessing the wallet. Consequently, they can transfer cryptocurrency to their own accounts while the legitimate owner retains the original device.
Although this incident involved substantial losses, overall cryptocurrency theft has declined this year. TRM Labs reported that hackers stole USD$972 million during the first half of 2026, down from USD$2.3 billion during the same period in 2025.
Additionally, the number of successful attacks continued to increase despite lower total losses. TRM Labs recorded 207 cryptocurrency hacks during the first six months of 2026, the highest total for any comparable period.
Some victims expressed frustration that they had trusted hardware wallets to provide maximum protection. Tim Lamb, managing director at EquityEdge Studio, urged authorities through social media to identify those responsible after losing two Bitcoin that he had planned to leave to his children.
Goodman said the attack forced him to reconsider his confidence in both Bitcoin and hardware wallets. He questioned whether ordinary investors should rely on technology that remains difficult for most people to fully understand.
.