All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Coldcard bug led to $100M in Bitcoin hacks

Created at 17 Aug · 2:06 PM1 source↑ Market-relevant
IN SHORT

A flaw in Coldcard's seed generation code, unnoticed for years, allowed attackers to steal over $100 million in Bitcoin from thousands of users. The vulnerability was in how the wallet's secrets were generated, not the hardware itself.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

$100 millionestimated stolen bitcoin value
1,596 bitcointotal stolen bitcoin
7,300affected addresses
15estimated attackers
18.25 bitcoinJonathan Goodman's reported loss
$1.17 millionvalue of Goodman's loss at time of attack
2021year bug was introduced
May 2025date O'Beirne raised concerns

Who's Involved

Jonathan Goodman
Coldcard user who lost over $1.17 million in Bitcoin
Galaxy Research
Provided high-confidence estimate of stolen funds
Alex Thorn
Head of Galaxy Research, estimated number of attackers
Coinkite
Maker of the Coldcard wallet
James O’Beirne
Bitcoin developer who identified the seed generation bug
Peter Gray
Coinkite co-founder, identified as author of bug-containing code
Bobby Gray
Founder of TEXITcoin, commented on hardware wallet security
Coldcard bug led to $100M in Bitcoin hacks

↳ Why This Matters

This incident undermines the trust in hardware wallets, which are considered one of the most secure methods for storing cryptocurrency. The discovery of a long-standing bug in a widely used device raises concerns about the security of other hardware wallets and the broader cryptocurrency ecosystem.

Key facts

  • A bug in Coldcard's seed generation code allowed hackers to steal over $100 million in Bitcoin.
  • The vulnerability affected approximately 7,300 users and 1,596 bitcoin.
  • The flaw was introduced during a major software update in 2021 and went unnoticed for years.
  • Bitcoin developer James O’Beirne identified the code changes as originating from Coinkite co-founder Peter Gray.
  • The bug caused the wallet to use a less secure software generator for randomness instead of a dedicated hardware generator.

A significant security flaw in Coldcard hardware wallets has led to the theft of over $100 million in Bitcoin from approximately 7,300 users. The vulnerability, present for years, was not in the hardware's air-gapped nature but in the process used to generate the secret seed phrases that protect users' funds.

Jonathan Goodman, a Toronto entrepreneur, reported losing 18.25 bitcoin, valued at over $1.17 million at the time, on July 29, stating he had followed all recommended security practices. His loss was part of a larger series of attacks, with Galaxy Research estimating that 1,596 bitcoin were stolen. At least 15 different attackers were believed to be exploiting the flaw, which did not require physical access to the devices.

The core security premise of hardware wallets like Coldcard is that private keys never leave the secure chip. However, the bug in Coldcard's seed generation meant that the secrets were derived from a less robust source. This flaw was introduced during a major software update in 2021, identified by Bitcoin developer James O’Beirne, who traced the problematic code to a library developed under the pseudonym "switck." O’Beirne identified "switck" as Coinkite co-founder Peter Gray.

Instead of using a dedicated hardware random number generator, the wallet was configured to use a simpler software generator that relied on device and timing data. This information, not being completely random, allowed attackers to narrow down the possibilities and test seeds more effectively, ultimately compromising the security of users' funds.

Frequently asked questions

A seed phrase, also known as a recovery phrase or mnemonic phrase, is a list of words that can be used to recover your cryptocurrency wallet if you lose access to your device or forget your password.

A configuration error caused the Coldcard wallet to use a less secure software generator for randomness when creating seed phrases, rather than its intended hardware random number generator. This made the seed phrases predictable and guessable by attackers.

An air-gapped system is a computer or device that is physically isolated from unsecured networks, such as the internet. This is a key security feature for hardware wallets.

Users should monitor for firmware updates from Coinkite and apply any patches released to address the vulnerability. It is also advisable to review security practices and consider the implications of this breach.

What Happens Next

01Coinkite is expected to release a patch for the vulnerability.
02Users are advised to update their Coldcard firmware once a fix is available.
03Further audits of hardware wallet seed generation processes may be initiated.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Jonathan Goodman reported losing 18.25 bitcoin, worth over $1.17 million, on July 29.
The loss was part of a larger hack impacting thousands of Coldcard users.
Galaxy Research estimated 1,596 bitcoin, over $100 million, stolen from about 7,300 addresses.
At least 15 attackers exploited the flaw without physical access to devices.
The vulnerability was in Coldcard's seed phrase generation process.
A bug entered Coldcard during a 2021 software change, replacing code with new equivalents.
Bitcoin developer James O’Beirne identified the "switck" account as Coinkite co-founder Peter Gray.
O’Beirne questioned the randomness source, tracing it to libngu, in May 2025.

Sources

T1
How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked fundsCoinDesk

Related Stories

Crypto hardware wallet owners face new risks from data breaches
17 Aug · 1:31 PM
Harmony to Roll Back Blockchain After Exploit, Discarding 109,000 Transactions
17 Aug · 12:45 PM
Ethereum's Hegotá Upgrade Considers Privacy Enhancements and Transaction Customization
17 Aug · 12:21 PM
Bitcoin Holders Bet on Fixed Supply Over Price Swings
17 Aug · 11:36 AM
Bits of Gold data breach affects 200,000 customers
17 Aug · 12:11 PM