S&P 5007,785.76▼0.2% Nasdaq26,729.16▼0.3% Dow53,732.41▼0.2% Russell 2K3,068.42▲0.5% 10-Yr4.70%+6bp VIX14.25−0.38 WTI$82.40▲1.4% Gold$4,432.00▲1.6% EUR/USD1.157▲0.4% BTC$64,382▲2.5% Nikkei68,309▲1.2%
At close · Fri, Aug 14, 2026
Daily Market Updates.

Crypto

HomeCryptoMarket StructureColdcard hardware wallet flaw led to $100 million in s…

Coldcard hardware wallet flaw led to $100 million in stolen bitcoin

Galaxy Research estimates 1,596 bitcoin worth over $100 million was taken from about 7,300 addresses, with at least 15 attackers exploiting the vulnerability.

A bug in Coldcard’s code went unnoticed for years, and multiple attacks tied to the flaw emptied users’ wallets, including one reported loss that exceeded $1 million, according to CoinDesk. Toronto entrepreneur Jonathan Goodman said that on July 29 every wallet he had was emptied and that he lost 18.25 bitcoin, worth just over $1.17 million at the time of the theft.

CoinDesk said the broader incident affected thousands of Coldcard users. Galaxy Research estimated it had high confidence that 1,596 bitcoin, worth over $100 million, was stolen from about 7,300 addresses in a series of attacks.

CoinDesk reported that Galaxy Research head Alex Thorn estimated on Aug. 4 that at least 15 different attackers were exploiting the weakness, and that none required physical access to the devices. The outlet said a hardware wallet’s security model depends on secrets never leaving the chip, so with no internet connection there should be no way in beyond physical access.

CoinDesk also explained that the vulnerability was not in the wallet itself, but in how the secret password, or seed phrase, protecting users’ coins was generated. It noted that while hardware wallets are designed to be safer than internet-connected software wallets, they are not infallible.

Latest closeBitcoin $64,381.79 ▲2.5%

More like this

Sources

Get the close, explained.

One email every trading day: what moved, why it moved, and what's on deck tomorrow. Read in 3 minutes.

Free. Unsubscribe anytime.