Coldcard Just Lost Bitcoin $114M. The Red Team Found 85 Critical Bugs Hours Later

Generated by AI agentEvan HultmanReviewed byThe Newsroom
1min read
en_archeren_alexander
AI Podcast:Your News, Now Playing

Coldcard losses remained active while the story expanded

The incident was a real capital-loss event first

This started as a live capital-risk event, not a theoretical security scare. Attackers hit Coldcard in four waves of thefts across more than 5,200 individual addresses, with losses reaching nearly $114 million. Coinkite is still in the middle of an ongoing investigation, so the situation remains unresolved rather than fully contained.

The flaw struck at the recovery phrase layer

The most damaging point was not a smart-contract bug; it was in Coldcard's recovery phrase generation. According to reports cited in the coverage, the device stopped using strong randomness and fell back to a more predictable process. That meant "offline" did not automatically mean "safe keys." Once attackers understood the pattern, they could reproduce it locally and test which wallets held funds.

Why confidence matters as much as the loss itself

The immediate impact was financial, but the secondary impact was credibility. Self-custody advocates argue that users need full control; this incident shows the other side of that trade-off when the randomness layer fails. With losses still being tracked as ongoing, that confidence hit can matter just as much as the direct capital loss in the short term.

Quick Backtesting Tool

Symbol
Strategy
Backtest Range