Hackers breached a Bitcoin cold wallet, losing over $86 million after discovering a seed phrase vulnerability.

107

A cold wallet, considered the most secure for storing Bitcoin, was hacked after a vulnerability in its system was discovered, allowing hackers to create seed phrases and steal over $86 million worth of Bitcoin from more than 4,500 user wallets.

On August 3, 2569, at 10.28:XNUMX a.m., Bloomberg News reported that Hackers discovered a vulnerability in the software of Coldcard, a cold wallet for Bitcoin, widely regarded as one of the most secure ways to store digital assets. This allows malicious actors to continuously steal tens of millions of dollars worth of Bitcoin from users.

Coinkite Inc., a Canadian manufacturer of Coldcard devices, issued a warning to users late last week. that A security vulnerability has been discovered in the key generation system used to protect cryptocurrencies, putting some wallets at risk.

Information from Galaxy Research. specify that By Monday, approximately 1,367 BTC, worth around $86 million, had been transferred out of more than 4,500 wallets.

Coldcard is a hardware device for storing Bitcoin as a cold wallet. It operates offline and is not connected to the internet, making it considered one of the most secure ways to store digital assets.

however The engineering team at Block Inc. revealed that Coldcard's software has a flaw in its seed phrase generation process, resulting in predictable phrases due to problems with the random number generation method.

Aneirin Flynn, Chief Executive Officer of cybersecurity company Failsafe. said This incident reflects that storing cryptocurrency offline is not always secure, especially if the device used to generate the code is faulty.

"The device is responsible for generating passwords. If there's a problem with the mathematical process behind it, those passwords can be reverse-calculated."

One of the victims was Jonathan Goodman. said At first, he thought he wouldn't be affected, but when he checked his wallet, he found a large number of withdrawals.

"The moment I opened my bags, I knew it was over because I saw the withdrawal transaction history in red. Between 9:36 PM and 9:43 PM on July 29th, all three of my bags were emptied."

Block's research team explained that the problem stems from how Coinkite designed its Random Number Generator to create seed phrases. In some cases, the fallback mechanism uses predictable values, such as device serial numbers, instead of truly random numbers.

This vulnerability allowed hackers to systematically calculate users' seed phrases before transferring Bitcoin out of their wallets. As of Friday, the estimated damage was around $38 million, but it rapidly increased throughout the weekend to reach $86 million.

Coinkite confirmed via its company website that wallets built with affected firmware versions are vulnerable and has released a new firmware version to fix the issue for all affected devices. Users are advised to update their software as soon as possible.

The incident has garnered significant attention in the crypto community, with both company executives and crypto influencers commenting on the impact on user trust.

Although cryptocurrency theft in 2569 will decrease compared to the previous year, Information from TRM Labs.Specifies that In the first half of this year, the value of cryptocurrency stolen still reached $972 million, although this is down from $2.3 billion during the same period in 2025. However, the number of hacking incidents increased to 207, the highest on record for the first six months of the year.

refer : www.bloomberg.com

 

Read related news





Money & Banking Magazine