$89 MILLION GONE: THE COLD WALLET BUG SHAKING BITCOIN SECURITY
A Bitcoin wallet is supposed to be the place where your coins are safest. But a software flaw in Coldcard hardware wallets has turned that promise into a major security warning after suspected losses climbed to nearly $89 million.

For years, one of the golden rules of Bitcoin has been simple: keep your keys away from the internet. Cold wallets were built around that idea.
Your Bitcoin stays offline, Your private keys stay on a physical device. Hackers cannot simply break into an exchange account, steal a password or take control of your computer.
Then came an attack that challenged the assumption.
Researchers say more than 1,000 Bitcoin worth about $70 million was drained from 1,196 Coldcard wallet addresses in just 41 minutes on July 30. Galaxy Research later identified two additional suspected waves, taking its estimated total to about 1,367 BTC, worth approximately $88.6 million, across 4,585 addresses.
And here's the unsettling part:
The attackers did not need to touch the wallets. The problem was buried inside the software used to create some of the wallets' recovery seeds.
A recovery seed is essentially the master key to a Bitcoin wallet. From it, the wallet's private keys and addresses are generated. It is supposed to be so unpredictable that guessing it through computation is practically impossible.
But a firmware error in certain Coldcard versions weakened that randomness.
According to Block's investigation, a configuration error caused affected Coldcard firmware to bypass the device's hardware random-number generator during seed creation and fall back to a weaker software-based process. That meant some supposedly random seeds could potentially be reconstructed by an attacker who understood enough information about the device and its random-number generation.
Think of it this way.
Imagine putting your money inside a safe with an almost impossible combination.
The safe itself is strong.
The door is locked.
Nobody can walk up and open it.
But what if the machine that generated the combination was quietly producing combinations from a much smaller list than you thought?
The safe could remain untouched while someone figures out the combination from the outside.
That is the concern here.
Researchers were able to analyse the blockchain and identify a large cluster of wallets whose transactions showed patterns consistent with a systematic sweep. Galaxy found that 1,082.65 BTC moved during the initial 41-minute attack window, across six blocks.
Because Bitcoin's blockchain is public, an attacker can generate candidate wallet seeds, derive the addresses associated with them and compare those addresses with funds visible on the blockchain.
No physical wallet needs to be connected.
No victim needs to click a suspicious link, No exchange account has to be hacked.
The blockchain itself can become the checking ground.
And that is what makes this incident particularly uncomfortable for the self-custody community.
Coldcard maker Coinkite has released fixed firmware for the affected models. But there is an important catch: updating the device does not repair a recovery seed that was already generated using vulnerable firmware.
Users whose seeds were generated under affected conditions need to create a new seed using fixed firmware and move their Bitcoin to the new wallet.
Coinkite says the affected firmware includes Mk2 and Mk3 versions 4.0.1 through 4.1.9, while seeds generated on certain earlier versions of the Mk4, Mk5 and Q are also affected, although the level of exposure differs. The company says users who supplied at least 50 fair, independent and private dice rolls when creating their seed are not considered at risk from this specific random-number-generation flaw alone.
A strong, unique BIP-39 passphrase can provide another layer of protection, but Coinkite still recommends migration for affected users.
There is another reason the incident is still developing.
Galaxy has warned that the activity may not be finished. Its later analysis identified additional suspected waves and said roughly 600 suspected attacker-controlled addresses had been reported to investigators and other relevant organisations. It also stressed that its findings are based on blockchain analysis and that not every address has been independently confirmed as having been generated with vulnerable Coldcard firmware.
Coinkite has also acknowledged the seriousness of the incident.
The company has apologised to users and said its investigation is continuing. It is working with blockchain investigators and law enforcement while it tries to determine the full scope of the problem.
For Bitcoin users, the lesson goes beyond one wallet brand.
Self-custody does not mean zero risk.
It means the responsibility for security moves closer to the owner.
A hardware wallet can protect against online attacks, phishing and compromised computers, but the security chain begins before the first Bitcoin ever enters the wallet. If the recovery seed is generated incorrectly, the problem can follow that seed wherever it goes.
That is why “offline” does not automatically mean “untouchable.”
The Coldcard incident is a reminder that Bitcoin security is not only about protecting the device.
It is also about protecting the process that creates the keys.
And when millions of dollars can disappear in less than an hour without anyone touching the physical wallet, that distinction suddenly becomes very real.
For anyone affected, the message from Coinkite is straightforward: update the device, generate a new recovery seed and carefully move funds from the affected wallet. Do not assume that installing new firmware magically fixes an old seed.
Because in Bitcoin, the strongest-looking lock in the world is only as good as the key behind it.
Keep your Bitcoin moving, but keep it protected
Bitcoin gives you control over your money. That control comes with responsibility and when it is time to move your BTC, you want the process to be just as straightforward as the technology is powerful.
With Monica, you can convert Bitcoin and other cryptocurrencies to naira while handling everyday payments, bills and subscriptions from the same app.
When you're ready to turn your Bitcoin into everyday value, let Monica handle the move. Download Monica Here: https://monica.cash/app today.