How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds

A security vulnerability in Coldcard hardware wallets has led to the theft of approximately $100 million in Bitcoin from thousands of users. The flaw existed in the seed phrase generation process, undermining the security premise of offline cold storage.
Why it matters
This incident highlights significant risks in the cryptocurrency ecosystem, specifically regarding the reliability of hardware security devices that users trust to protect their assets.
The hardware wallet holding his keys, a Coldcard, had never been connected to the internet. He kept it stored in a safe deposit box. The seed phrase, which he’d never shared with anyone, was stored in a second safe deposit box. But on July 29, Goodman said, every wallet he had was emptied, every last satoshi stolen. The Toronto entrepreneur reported losing 18.25 bitcoin, worth just over $1.17 million at the time of the attack.
“Perhaps the hardest part about this is that I did everything right,” he wrote in an Aug 1 X post .
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in