Hackers have reportedly drained nearly $89 million in Bitcoin from more than 1,000 wallets in recent attacks linked to a software vulnerability affecting certain Coldcard-generated wallets.
A major cryptocurrency security incident has raised fresh concerns among Bitcoin investors after hackers reportedly drained more than 1,000 Bitcoin from nearly 1,200 digital wallets in a series of recent attacks.
As per blockchain analysis referenced by security researchers, the first attack on July 30 led to the theft of over $70 million in Bitcoin within a mere 41 minutes. Subsequent suspicious activities detected later increased the estimated total losses to almost $89 million.

What Happened to the Bitcoin Wallets?
The incident is associated with Coldcard, a hardware wallet intended for users to securely store Bitcoin offline. Hardware wallets are typically regarded as more secure than keeping cryptocurrency on online exchanges, as they keep private keys separate from internet-connected devices.
Nevertheless, researchers discovered that a flaw in the software or firmware might have compromised the method used to create specific wallet recovery phrases.
Galaxy Research reported that more than 1,000 Bitcoin were drained from 1,196 wallets during a 41-minute period on July 30. Researchers later identified two additional suspected waves of activity, increasing the estimated financial impact to approximately $89 million.
Importantly, researchers have cautioned that blockchain analysis cannot independently confirm that every affected wallet was created using the vulnerable software.
Software Flaw Could Have Made Recovery Phrases Predictable
A recovery phrase, sometimes called a seed phrase, is one of the most important security components of a cryptocurrency wallet. It can be used to restore access to the funds controlled by a wallet.
According to security researchers, a coding mistake in certain Coldcard firmware versions may have resulted in insufficient randomness when some recovery phrases were generated.
That weakness could potentially have reduced the number of possible combinations an attacker needed to investigate. A sufficiently capable attacker could then use blockchain information and computational analysis to identify vulnerable wallets and move their Bitcoin without physically accessing the hardware device.
This makes the incident particularly significant because the attack reportedly did not require hackers to steal the physical Coldcard devices.
Coldcard Maker Releases an Update
Coinkite, the company behind Coldcard, has released a software update intended to prevent the vulnerability from affecting newly generated wallets.
However, simply updating the device does not necessarily fix a recovery phrase that was already generated using vulnerable firmware.
The company has advised affected users to generate a completely new recovery phrase using updated software and transfer their Bitcoin to the newly secured wallet. Coinkite also warned that importing the same old recovery phrase into another wallet does not solve the problem because the weakness is associated with the recovery phrase itself.
Coinkite CEO Rodolfo Novak also publicly apologized and urged users who may be affected to take action quickly.
Some Users May Not Be Affected
Researchers and the wallet manufacturer have emphasized that not every Coldcard user is necessarily at risk.
According to the reported security guidance, users who generated their recovery phrases using strong external randomness, including at least 50 private dice rolls, are not affected by this particular vulnerability alone.
However, users who are unsure how their wallet was originally generated have been encouraged to take precautions and consider moving their Bitcoin to a newly generated, secure wallet.
Why the Attack Is Significant for Bitcoin Security

The incident is notable because hardware wallets are specifically designed to protect cryptocurrency from online attacks.
Bitcoin itself was not hacked. Instead, the incident involved a weakness in the software used to generate certain wallet credentials.
Bitcoin transactions rely on cryptographic private keys. If an attacker obtains or successfully reconstructs the information needed to control a wallet, the Bitcoin network will generally treat a properly signed transaction as authorized.
This highlights an important distinction: the security of Bitcoin’s blockchain and the security of software or hardware used to manage Bitcoin are not the same thing.
What Bitcoin Wallet Users Should Do
Cryptocurrency users should take extra care when managing recovery phrases and private keys.
People using potentially affected wallet software should first check the manufacturer’s official security guidance and determine whether their recovery phrase was generated by a vulnerable version.
If a recovery phrase is believed to be vulnerable, users should create a new recovery phrase using secure, updated software and move funds to the new wallet.
Users should also remember:
- Never share a recovery phrase with anyone.
- Never enter a seed phrase into an unknown website.
- Do not assume that installing a firmware update automatically repairs an old vulnerable seed.
- Keep recovery phrases offline and protected from unauthorized access.
- Verify wallet addresses carefully before sending large amounts of cryptocurrency.
- Follow official security advisories rather than relying on social-media claims.
Broader Warning for the Crypto Industry
The Coldcard incident highlights that the security of cryptocurrency relies on factors beyond just blockchain technology.
Even with funds kept offline, weaknesses in random-number generation, wallet software, firmware, or key-management practices can pose significant risks.
The reported theft of approximately $89 million illustrates how swiftly attackers can take advantage of a vulnerability once at-risk wallets are recognized on the blockchain.
Security researchers are actively investigating the transactions to assess the complete extent of the incident. In the meantime, affected users are advised to take prompt action instead of waiting for additional updates.
Final Takeaway
The recent Bitcoin wallet attacks have highlighted a critical lesson for cryptocurrency holders: cold storage does not automatically eliminate every security risk.
More than 1,000 Bitcoin were reportedly stolen from 1,196 wallets during the initial 41-minute attack, while subsequent suspicious activity brought estimated losses close to $89 million.
The incident seems to be linked to a software defect that impacts the creation of specific Coldcard recovery phrases, rather than indicating a breach of the Bitcoin blockchain itself.
For users who might have produced at-risk recovery phrases, it may be crucial to establish a new secure wallet and move their funds. As the adoption of cryptocurrency expands, this incident highlights the necessity of secure software development, robust randomness, and meticulous management of private keys.