๐Ÿ“… Sunday, 6 September 2026 ยท --:-- UTC Follow us
Ecosystem โ–ผ
ID EN
Peretas Kuras $70 Juta Kripto dari 1.196 Dompet Coldcard - Tapi Celahnya Sudah Ada Sejak Tiga Tahun Lalu

Hackers Drain $70M in Crypto from 1,196 Coldcard Wallets - But Flaw Dates Back Three Years

The numbers have swelled once again. According to the latest findings from Galaxy Research, losses resulting from an exploit on Coldcard hardware wallets have now reached $70.2 million, or 1,082.65 BTC. These funds were drained by hackers from 1,196 distinct wallet addresses. The new figure has nearly doubled from the initial estimate made by AnchorWatch CEO Rob Hamilton, who originally pegged losses at around $38 million, or 594 BTC, across 500 victim wallets.

All coins vanished from the wallets within a 41-minute window. The mass drain occurred on July 30, 2026, precisely between 01:10 and 01:51 UTC, spanning transaction records from blocks 960,183 to 960,191 on the Bitcoin network. Galaxy’s on-chain tracking team detected an identical transaction pattern across every withdrawal. The hackers set a fixed fee rate of 30 satoshis per vB and moved all coins without leaving any change output. This uniform and rapid execution trail indicates that the attackers deployed an automated bot to wipe out the funds before victims could react.

A Ticking Time Bomb from a 2021 Update

The roots of this incident were planted three years ago. The vulnerability stemmed from a build error in Coldcard’s March 2021 firmware released by its manufacturer, Coinkite. When wallets were initialized on this flawed version, the seed phrase generation process inadvertently drew data from a software fallback generator. Normally, recovery phrases should have been generated by the authentic hardware random number generator designed to prevent compromise.

The failure of the hardware randomness system made the recovery seed combinations generated during that period significantly more susceptible to being guessed. In response to the breach, Coinkite has released an emergency hotfix to remove the software fallback generator from their system.

Unfortunately, this emergency update only protects future wallet creation. The patch cannot fix or reinforce vulnerable seed phrases that were already generated in the past. The only recourse for those affected by the March 2021 update is to generate a new recovery key using the latest version and migrate all their funds to a secure wallet.

Rethinking Storage Strategies

This mass breach shatters the assumption that cold storage is entirely immune to hacking. Former Binance CEO Changpeng Zhao, also known as CZ, issued a stark warning to the community via his X account, emphasizing that no hardware wallet guarantees 100% security.

Rather than relying on a single brand or device, CZ advised Bitcoin holders to diversify where they store their assets. Spreading coins across multiple locations serves as a final layer of defense when primary systems fail. When devices built for resilience turn out to harbor factory flaws, distributing storage across different baskets is a sensible line of defense.

Originally reported by Decrypt.


Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.

Share this article:
๐Ÿ“ฉ KABAR BITCOIN IN 1 MINUTE

Daily crypto news, straight to your inbox

A 1-minute digest for people always on the move. Free, unsubscribe anytime.

Total
0
Share