A security hack has once again rocked crypto. Since Thursday, Bitcoin owners who store their crypto with Coldcard, which offers a form of hyper-secure storage known as hard wallets, have experienced four waves of thefts that have affected more than 5,200 individual addresses. An on-chain analysis by blockchain intelligence firm Galaxy Research revealed that the hackers have already moved approximately 1,816 Bitcoin, worth nearly $116 million, off those wallets.
It remains unclear who is behind the hack. While recent large crypto thefts have often been attributed to state-backed groups in North Korea or Russia, investigators have not yet linked this incident to any specific actor.
Coldcard, made by Canadian technology firm Coinkite, is a small hardware device that keeps Bitcoin keys offline, marketed as “cold” storage for long‑term holders. That offline design was supposed to make it one of the safest places to park Bitcoin but a flaw in Coldcard’s process created a fatal vulnerability.
The weakness is rooted in a 2021 Coldcard software update that changed the way the wallet generated its recovery phrase—a series of random words, such as “pepper” or “floorboard” for instance, that provide a means of regenerating the dozens of random characters that make up a Bitcoin address.










