Close Menu
Truth Republican
  • Home
  • News
  • Politics
  • Business
  • Guns & Gear
  • Healthy Tips
  • Prepping & Survival
  • Videos
Facebook X (Twitter) Instagram
Truth Republican
  • Home
  • News
  • Politics
  • Business
  • Guns & Gear
  • Healthy Tips
  • Prepping & Survival
  • Videos
Newsletter
Truth Republican
You are at:Home»Business»Coldcard wallet attack drains up to $89M in Bitcoin from 1,200+ addresses
Business

Coldcard wallet attack drains up to $89M in Bitcoin from 1,200+ addresses

Buddy DoyleBy Buddy DoyleAugust 3, 2026No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp
Coldcard wallet attack drains up to M in Bitcoin from 1,200+ addresses
Share
Facebook Twitter LinkedIn Pinterest Email

Owners of a popular bitcoin storage device are being urged to protect their cryptocurrency after security researchers said a software flaw may have allowed attackers to steal roughly $70 million worth of bitcoin in less than an hour.

Forbes first reported the attacks, which researchers at Galaxy Research say drained more than 1,000 bitcoin from 1,196 digital wallets in just 41 minutes on July 30.

Galaxy later identified two additional suspected waves of suspicious activity, bringing the estimated losses to nearly $89 million.

CRASHSTEALER MAC MALWARE STEALS PASSWORDS AND WALLETS

The firm cautioned that its findings are based on blockchain analysis and that it has not confirmed every affected wallet was created using the vulnerable software.

The issue involves Coldcard, a handheld device many cryptocurrency investors use to store bitcoin offline instead of leaving it on a cryptocurrency exchange. Often called a “hardware wallet,” the device is designed to keep hackers from accessing a user’s bitcoin over the internet.

According to a security advisory from Block’s Bitcoin Engineering and Security team, a coding mistake in certain versions of Coldcard may have weakened one of the wallet’s key security features.

PAIDWORK BREACH EXPOSES 23M USER RECORDS

Block said the software bug may have made some of those recovery phrases predictable enough for sophisticated attackers to figure them out under certain circumstances, potentially allowing them to steal bitcoin without ever physically touching the wallet.

The company said it released its findings because it believes the attacks are still happening, though researchers cautioned they are continuing to study exactly how the vulnerability is being exploited.

Canadian company Coinkite, which makes Coldcard, has since released a software update to prevent the problem from affecting newly created wallets.

KARR BLUETOOTH FLAW EXPOSES 2.2M CARS TO THEFT RISK

Bitcoin representation

However, the company warned that simply installing the update will not protect people who already created a recovery phrase using the affected software.

Instead, Coinkite is urging those users to create a brand-new recovery phrase using the updated software and move their bitcoin into the newly secured wallet.

“Updating the firmware does not repair a seed that was generated by affected firmware,” the company said in a security advisory. “A new seed must be generated and the funds migrated to the new wallet.”

Coinkite also warned that moving the same recovery phrase into another wallet does not solve the problem because the weakness follows the recovery phrase itself, not the physical device.

Coinkite CEO Rodolfo Novak issued a public apology on X, saying the company was “heartbroken” and taking “full accountability for the firmware bug.”

“I’m sorry and I’m devastated,” Novak wrote. “Our team is heartbroken about yesterday’s news.”

Novak urged customers to act immediately.

“If you generated a seed using a Coldcard wallet, move your funds now, using our updated best practices, before reading further,” he wrote.

He also asked the public to help spread the warning.

“If you know anyone who owns a Coldcard, please make sure they see this,” Novak wrote. “Some affected users may not be watching social media right now, and every hour matters.”

Novak said Coinkite is still working to determine exactly how many people may have been affected and plans to publish a detailed explanation of what went wrong after its investigation is complete.

“We do not have full attribution or scope of the issue yet, and we won’t speculate until our full technical evaluation is complete,” Novak wrote.

The company said it will also help affected customers who want to file police reports or insurance claims and is cooperating with blockchain investigators and law enforcement agencies.

The warning quickly spread across the cryptocurrency industry.

“If you’re using a COLDCARD, any version firmware or MK, migrate your funds immediately,” Jan3 CEO Samson Mow wrote on X. “If you know someone who is, let them know ASAP… Attacks are ongoing so do it quickly.”

While the initial warning focused on older Coldcard devices, Coinkite has since expanded the list of affected products to include additional models and software versions.

The company also said customers who created their recovery phrase using at least 50 private dice rolls are not affected by this specific flaw alone. However, Coinkite recommends that anyone who is unsure how their wallet was set up create a new recovery phrase and move their funds as a precaution.

Bitcoin on a digital screen

Block emphasized that none of its own products or customers are affected by the vulnerability. The company said it published its findings after working with anonymous security researchers and receiving reports from Coldcard users.

Separately, developers of Jack Dorsey’s Bitkey wallet said they are investigating a different reported issue involving their product but are not advising customers to stop using the wallet.

“Our recommendation is to continue to use your Bitkey normally,” Bitkey developer Clay Garrett wrote on X.

Garrett said the reported issue would require “exceptional circumstances” to exploit and would not give an attacker enough information to steal customers’ funds.

“Our assessment is this presents no risk of remote drains or immediate funds loss,” Garrett wrote.

FOX Business reached out to Coinkite, Galaxy Research, Block, the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the Royal Canadian Mounted Police (RCMP), the Canadian Centre for Cyber Security and Chainalysis for comment but did not immediately receive a response.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleChelsea Green captures WWE gold at SummerSlam in ladder match
Next Article Why You’re NOT Safe Without These 17 Home Defense Gadgets On AMAZON!

Related Articles

Myspace seeking a revival as its owners plan comeback effort for once-popular social media platform

Myspace seeking a revival as its owners plan comeback effort for once-popular social media platform

August 3, 2026
Nearly 23,000 pounds of Ukrop’s baked spaghetti and chicken cobbler recalled over metal sliver concerns

Nearly 23,000 pounds of Ukrop’s baked spaghetti and chicken cobbler recalled over metal sliver concerns

August 2, 2026
Minnesota’s ban on crypto ATMs goes into effect after citizens report losing nearly  million in scams

Minnesota’s ban on crypto ATMs goes into effect after citizens report losing nearly $1 million in scams

August 1, 2026
Nearly 12 million bottles of Rohto eye drops over sterility concerns, FDA announces

Nearly 12 million bottles of Rohto eye drops over sterility concerns, FDA announces

August 1, 2026
Frozen burritos sold at Costco prompt public health alert over undeclared allergen

Frozen burritos sold at Costco prompt public health alert over undeclared allergen

August 1, 2026
LARRY KUDLOW: How about a Reagan-style reconciliation tax cut? All right?

LARRY KUDLOW: How about a Reagan-style reconciliation tax cut? All right?

August 1, 2026
Trump regulators propose overhaul of ‘weaponized’ Community Reinvestment Act, say rule funded activist groups

Trump regulators propose overhaul of ‘weaponized’ Community Reinvestment Act, say rule funded activist groups

July 31, 2026
More than 132K ‘Skull Strobe’ fireworks recalled over explosion risk, serious burn hazards

More than 132K ‘Skull Strobe’ fireworks recalled over explosion risk, serious burn hazards

July 31, 2026
Fed dissenters warn inflation could become entrenched without monetary policy tightening now

Fed dissenters warn inflation could become entrenched without monetary policy tightening now

July 31, 2026
Don't Miss
Why You’re NOT Safe Without These 15 SURVIVAL Gear & Gadgets?

Why You’re NOT Safe Without These 15 SURVIVAL Gear & Gadgets?

Todd Blanche moves closer to confirmation after rescinding .8B fund

Todd Blanche moves closer to confirmation after rescinding $1.8B fund

SMALLEST But DEADLIEST GUNS for Home Defense 2025

SMALLEST But DEADLIEST GUNS for Home Defense 2025

Brewers ace Jacob Misiorowski unloads on Angel Stadium mound after embarrassing Angels loss

Brewers ace Jacob Misiorowski unloads on Angel Stadium mound after embarrassing Angels loss

Latest News
Trailblazing former Republican Rep Kay Granger dies at 83: ‘Broke barriers’

Trailblazing former Republican Rep Kay Granger dies at 83: ‘Broke barriers’

August 3, 2026
Deadliest animal in every US state revealed, from moose and bears to dogs

Deadliest animal in every US state revealed, from moose and bears to dogs

August 3, 2026
19 Incredible Tactical Military Gadgets You Can Actually Buy on Amazon

19 Incredible Tactical Military Gadgets You Can Actually Buy on Amazon

August 3, 2026
Myspace seeking a revival as its owners plan comeback effort for once-popular social media platform

Myspace seeking a revival as its owners plan comeback effort for once-popular social media platform

August 3, 2026
RFK Jr was right to confront CNN over Fauci coverage, say network was ‘scaring people’ during COVID-19

RFK Jr was right to confront CNN over Fauci coverage, say network was ‘scaring people’ during COVID-19

August 3, 2026
Copyright © 2026. Truth Republican. All rights reserved.
  • Privacy Policy
  • Terms of use
  • Contact

Type above and press Enter to search. Press Esc to cancel.