What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin

Hackers have exploited a software vulnerability in Coldcard hardware wallets, resulting in the theft of over $100 million in bitcoin. The flaw allowed attackers to reconstruct user seed phrases without physical access to the devices.
Why it matters
This incident highlights significant security risks in hardware wallets previously considered highly secure, impacting the trust of long-term cryptocurrency holders.
Hackers reportedly drained more than $100 million US worth of bitcoin from Coldcard hard wallets, according to blockchain intelligence firm Galaxy Research .
Here's what we know about the ongoing hack, who is affected and what you should do to secure your cryptocurrency.
Coldcard , created by Toronto-based company Coinkite, is also known as a hardware wallet — but it doesn't actually store any bitcoin for you.
Bitcoin remains on the public blockchain network, but a Coldcard adds an extra layer of security by storing "seed phrases" offline — without ever needing to be connected to the Internet — inside of the physical device.
"Seed phrases" are a sequence of random words, meant to be difficult or impossible to guess, which act as a master key to the bitcoin-only wallet.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in