0x0690ea030690…0690ea00
Coldcard Exploit Ties $111M in Losses to Private Key Weakness
At least $111M in bitcoin has been stolen through a Coldcard hardware wallet entropy flaw, with Galaxy projecting total losses above $130M and Blockaid CEO Ido Ben-Natan calling the incident crypto's 'original sin.'
Outputs
At least $111 million in bitcoin confirmed stolen via the Coldcard exploit, per Galaxy Research estimates published Friday.
Galaxy projects total losses will exceed $130 million as multiple threat actors continue exploiting the vulnerability.
K33 estimates more than 7,000 bitcoin addresses were targeted in the theft wave.
Roughly 75% of funds lost to crypto exploits in H1 2026 stemmed from private-key compromises, per Blockaid.
H1 2026 crypto losses topped $1 billion, a period Blockaid described as 'the most-hacked half-year on record.'
At least $111 million in bitcoin has been stolen through a flaw in Coldcard hardware wallets, with total losses expected to exceed $130 million, according to Galaxy Research estimates published Friday.
What did the attackers actually exploit?
The attack exploited a randomness weakness in how affected Coldcard devices generated wallet seeds, according to the wallet's manufacturer Coinkite and security firm Block, whose engineering teams analyzed the firmware. By reducing the entropy used during seed creation, the bug opened a path for attackers to reconstruct the private keys controlling user funds.
How does an offline device become the weak link?
Coldcard markets itself as an air-gapped device engineered to keep private keys offline. That pitch is now at the center of the incident, since the compromise occurred inside the secure element itself rather than through an online intrusion.
Wallet maker Coinkite published a technical backgrounder on the entropy issue. Block's engineering team separately documented a "predictable RNG fallback and 32-bit reseed" in the Coldcard firmware. Together, the disclosures point to a seed-generation pathway that produced deterministic outputs under certain conditions.
K33, a crypto research firm, said more than 7,000 bitcoin addresses were targeted in the wave of thefts. Galaxy flagged "multiple different threat actors" actively exploiting the vulnerability, suggesting the technique leaked quickly once the firmware behavior was understood.
Why does Blockaid's CEO call this crypto's "original sin"?
Ido Ben-Natan, CEO of blockchain security firm Blockaid, framed the incident as evidence of a structural weakness in how the industry handles custody.
"The fact that we govern who has access to our assets, whether that's from crypto or access to different pieces of data on the Internet, is generally derived historically by a password, and then after that, some sort of private key," Ben-Natan said during an interview with The Block's Starting Block on Friday. "It's a single-use kind of access to these things. Now there's beauty in that no one else can go in and have access to these things. The hardship in that is that it is a single point of failure."
"The learning here is just having your assets sit somewhere and forgetting about them and not thinking about them is not actually the solution because the pace of security is evolving," he added. "You have to either kind of constantly be paranoid or either outsource that decision-making process to someone else."
How dominant are private-key compromises as an attack vector?
Blockaid's latest crypto-crime report puts private-key compromise at the top of the threat list:
- ~75% of funds lost to crypto exploits in H1 2026 stemmed from private-key compromises
- H1 2026 losses exceeded $1 billion across the period Blockaid called "the most-hacked half-year on record"
- Incident counts surged alongside the dollar value of thefts
"The number of incidents that we've reported on in our H1 report here is just the tip of the iceberg," Ben-Natan said. "What we're actually reporting on here is a fraction of what is taking place."
Blockaid sells security and real-time threat monitoring services to wallets, exchanges and other crypto firms — a position that gives it visibility into the incident pipeline.
What comes next as AI reshapes the threat model?
Ben-Natan expects Coldcard to be the leading edge of a much larger problem as AI tooling lowers the cost of sophisticated offensive work. "Very soon everyone in the world is gonna have one of the best hackers in the world at their fingertips," he said, casting crypto as a "canary in the coal mine" for downstream cybersecurity.
The economic logic for attackers is straightforward, he argued: "If you think about the economics that a threat actor has ... they will do the thing that enables them to spend the least amount of time, the least amount of resources, in order to generate the highest reward."
With Galaxy projecting losses above $130 million and K33 continuing to track more than 7,000 affected addresses, the Coldcard disclosure is likely to remain an active on-chain investigation through the coming weeks as investigators trace flows across exchanges and mixers.
via x.com (Original)
More from Elena Vasquez
Show full bio
Staff writer covering marketplaces and e-commerce at Mempool Brief.
440 articles