Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked

August 3, 2026

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

August 3, 2026

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

August 3, 2026
Facebook X (Twitter) Instagram
Monday, August 3
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
News

Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked

Team-CWDBy Team-CWDAugust 3, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


An ongoing attack against a popular Bitcoin wallet has already led to the theft of an estimated $89m, according to researchers.

Coinkite’s Coldwallet is a Bitcoin-only hardware wallet which came under attack on July 30.

Galaxy Research tracked the initial wave of attacks, which drained 1,082.65 Bitcoin ($70m) from 1196 addresses over a 41-minute window. It traced the funds to four attacker-controlled addresses, claiming the activity was likely automated.

The research team identified a subsequent second and third wave on August 1, pushing the total stolen up to 1367 Bitcoin ($88.6m) and the victim address count to 4385.

“The Coldcard exploit is ongoing. Move Coldcard single-sig funds to safe locations immediately,” Galaxy Research said in a post on X (formerly Twitter) on August 2.

“We have reported ~600 addresses we believe to be hackers holding funds stolen from Coldcard-generated weak entropy addresses to federal investigators, industry compliance firms, and cross-industry cyber investigators.”

Read more on wallet-based threats: Cyber-Criminals Exploit Hardware Wallet to Steal Almost $30,000

A report from Block’s Bitcoin Engineering and Security team on July 30 claimed the incident stemmed from exploitation of a firmware vulnerability dating back to 2021.

Due to the bug, the wallet sometimes didn’t use a hardware-based random-number generator (RNG) to create users’ wallet seeds (master keys). Instead, it used a fallback generator which was deterministic in nature, meaning the numbers generated were not random enough to be cryptographically secure.

This meant attackers could reproduce the keys offline.

Coinkite Takes Action

Coinkite has now released updated firmware for every affected model and release track, and urged customers not to generate new seeds on affected models until they have installed the fix.

“Funds controlled by a seed generated on Mk2 or Mk3 version 4.0.1 (March 2021) through 4.1.9 inclusive are at risk if the seed was created without at least 50 fair, independent, private dice rolls and the funded wallet is not protected by a strong, unique BIP-39 passphrase,” it explained.

“Seeds generated on Mk4, Q and Mk5 before the fixed firmware releases are also affected, with about 72 bits of entropy rather than the expected 128 bits.”

There may currently be a fourth wave of attacks underway, according to a post on X by Galaxy Research head of firmwide research, Alex Thorn.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Team-CWD
  • Website

Related Posts

News

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

August 3, 2026
News

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

August 3, 2026
News

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

August 2, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How it preys on personal data – and how to stay safe

October 23, 2025

Why the tech industry needs to stand firm on preserving end-to-end encryption

September 12, 2025

What are brushing scams and how do I stay safe?

December 24, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.