#bitcoinhack
Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw #BitcoinHack #BitcoinTheft #BitcoinWalletSecurity
Coldcard Bitcoin Wallets Hit by Ongoing Attack Exploiting Key Generation Flaw
A software flaw in Coldcard hardware wallets has raised fresh concerns about the security of offline cryptocurrency storage after a software flaw in Coldcard hardware wallets allowed attackers to drain millions of dollars in Bitcoin.The attack has affected thousands of wallets using Coinkite’s Coldcard devices.  By August 3, about 1,367 Bitcoin worth US$86 million had been stolen from more than 4,500 wallets by August 3. Cold wallets are widely considered among the most secure ways to store cryptocurrency, as they keep private keys away from internet-connected devices. The Coldcard incident shows,offline storage cannot protect funds if there is a weakness in the process by which cryptographic keys are generated.  Predictable Seed Phrases Exposed Bitcoin Wallets The problem centers on how Coldcard devices generated the seed phrases used to recover wallets that will be used to recover and control a Bitcoin wallet in the central issue. A flaw in Coldcard's random-number generation process could produce predictable values instead of sufficiently random keys, according to a Block's engineering team analysis. Coldcard devices included a fallback mechanism based on deterministic information, including serial numbers.  The flaw allowed attackers to calculate vulnerable wallet keys and move the funds. The losses quickly mounted over the following days. According to initial reports, the loss amount on July 31 was approximately US$38 million, however within days, the amount had more than doubled.  Initially, Jonathan Goodman believed all three of his wallets would not be affected after checking. However, he discovered that all three had been emptied within minutes of one another on July 29.  Coinkite Releases Fixed Firmware Bitcoins controlled by seed phrases generated through affected firmware may be at risk, as confirmed by Coinkite. The flaw has also renewed scrutiny of hardware wallet security, regarding the assumptions surrounding hardware wallets, Coinkite has since released fixed firmware for the affected models and release tracks.  Although offline access eliminates many Internet-based attack routes, it does not eliminate vulnerabilities in the hardware, firmware, or cryptographic processes required to create those keys. The incident also shows that keeping a wallet offline does not remove every security risk. Despite being physically disconnected from the internet, a wallet may still be vulnerable if its cryptographic keys can be predicted or reconstructed.  Cold Storage Does Not Eliminate Cryptocurrency Risk The Coldcard attack comes as cryptocurrency theft continues to cause major losses across the industry. Approximately US972 million of cryptocurrency were stolen during the first half of 2026, substantially lower than the US2.3 billion stolen during the same period in 2025, according to TRM Labs. A total of 207 hacking incidents were recorded during the first six months of 2026, the highest total in the firm's history.  A TRM Labs report indicates that infrastructure and key compromises account for approximately 15 percent of incidents, yet 76 percent of losses were caused by them. The incident highlights a basic problem with self-custody that self-custody self-custody does not eliminate the risk of losing funds. Hardware wallets can greatly reduce online threat exposure. Their security still depends on how reliably the device generates and protects private keys.  Affected users should check whether their wallet seeds were generated with vulnerable firmware and follow Coinkite’s guidance that their wallet seeds were generated using vulnerable firmware and follow the manufacturer's remediation instructions.The Coldcard incident shows that keeping a hardware wallet offline is only one part of cryptocurrency security. The software and cryptographic processes used to generate its keys can be just as critical.
dlvr.it
August 21, 2026 at 7:46 AM
FBI closing in on Coldcard hack suspects! Over $11.8M in BTC stolen in 2026 due to a random number generation flaw in the wallet. Investigators linked attackers to a blockchain data service. Affected users urged to move assets ASAP. #Coldcard #BitcoinHack #Cybersecurity
August 19, 2026 at 2:29 AM
Phishing emails impersonating COLDCARD push a fake security audit and malicious diagnostic tool, tricking victims into installing ScreenConnect remote access software amid fears over a reported Bitcoin theft. #COLDCARD #ScreenConnect #BitcoinHack
COLDCARD security audit phishing attack installs remote access tool
A phishing campaign is abusing fears around the COLDCARD wallet vulnerability and the suspected $88.6 million Bitcoin theft to lure victims into installing ScreenConnect remote access software. The attackers impersonate COLDCARD with fake security audit emails and a bogus support site to pressure users into running a malicious diagnostic tool. #COLDCARD #ScreenConnect #Coldcard_Diagnostic_Tool #activeretirementrelocation.com
www.hendryadrian.com
August 5, 2026 at 8:30 PM
💥 $330M Bitcoin Hack Pushes Monero to 50% Surge 🚀

A recent $330M Bitcoin hack has caused Monero’s price to spike by 50%. Find out how privacy features are fueling the surge.

#Monero #XMR #BitcoinHack #CryptoNews
After a $330M Bitcoin Hack, Monero Surges 50% in a Stunning Turn of Events - Crypto Economy
A suspected hack involving 3,520 Bitcoin, valued at $330 million, has sent shockwaves across the crypto market. Turning a large part of it into Monero
crypto-economy.com
April 28, 2025 at 12:27 PM
May 17, 2025 at 6:50 PM