Coldcard Hardware Wallet Exploit Drains $38M+ in BTC
- Bitcoin
- Security
- Key Compromise

A firmware flaw in Coinkite Coldcard wallets allowed offline seed generation and address sweeping without physical access. Attackers drained 1,082.65 BTC (~$70M) from 1,196 addresses in 41 minutes on July 30 and hit 500 wallets for $38M on July 31. Total losses tracked at 1,367 BTC (~$89M) across 4,500 addresses. CT reacted with panic over hardware wallet trust after the details spread from on-chain analysis and The Hacker News report.
Incident Details
- Type
- OTHER
- Funds Lost
- $89M
- Status
- Ongoing
CT questioned hardware wallet security assumptions and Coinkite response