U.S. NATIONAL DEBT –
$39,890,263,441,627

Hackers Just Drained $110 Million From Bitcoin’s Safest Storage

Hackers Just Drained $110 Million From Bitcoin’s Safest Storage

For years, the answer to the question “how do you keep Bitcoin safe?” was simple: put it in cold storage.

Cold storage means keeping your cryptocurrency on a hardware device that never connects to the internet. No internet connection means no way for a hacker to reach your funds remotely. The keys stay on the device. The device sits in a drawer. Your Bitcoin sits safe.

That logic held for years. It stopped holding on July 30.

Hackers exploited a critical software flaw in Coldcard hardware wallets, made by Canada-based Coinkite, and drained approximately 1,755 Bitcoin worth roughly $110 million from nearly 5,000 wallets, according to Galaxy Research. Some of the drained wallets had not been touched in years. Their owners believed their funds were in the safest place possible.

They were not.

What Actually Happened

The attack did not break Bitcoin. That point is important and worth stating clearly. The Bitcoin blockchain itself was not compromised. No exchange was hacked. No centralized system failed.

What failed was the device people trusted to generate and store their Bitcoin keys.

The core of the problem was how Coinkite implemented the random-number generator in its Coldcard firmware. Strong cryptographic security requires genuine randomness when generating the seed phrases that protect a wallet. Coldcard had a fallback mechanism that instead produced keys using deterministic values — including, in some cases, the device’s own serial number. Deterministic means predictable. Predictable means attackable.

Once researchers at Block discovered the flaw, the math was straightforward. Attackers could systematically recalculate the seed phrases of affected wallets and drain them without ever physically touching a device. Every drained wallet stayed completely offline the entire time. Cold storage held. The firmware that generated the keys did not.

The attack came in waves. On July 30, approximately 594 Bitcoin worth around $38 million was drained from Coldcard Mk3 wallets. The losses climbed over the weekend as attackers expanded to other models. By Monday, Galaxy Research confirmed losses of more than 1,755 Bitcoin across roughly 5,000 addresses. Coinkite released emergency firmware updates for all affected models, but for those who had not yet moved their funds, the damage was done.

The Part That Should Make Everyone Pay Attention

This attack did not target careless crypto holders. It targeted some of the most security-conscious people in the entire digital asset ecosystem.

Coldcard is not a beginner’s wallet. It is widely considered the most security-hardened hardware wallet available, specifically designed for holders who take self-custody seriously. Its users tend to be long-term Bitcoin holders who have gone out of their way to avoid the risks of exchanges and online wallets. Many of the 5,000 drained addresses had not moved funds in years.

These were not people who clicked a phishing link. They did not keep their Bitcoin on an exchange. They bought a dedicated piece of hardware specifically designed to keep their crypto safe offline.

And they still lost everything in those wallets.

“If you’re using a Coldcard, any version firmware or MK, migrate your funds immediately,” Jan3 chief executive Samson Mow posted to X as the attack spread.

The Broader Security Picture

The Coldcard attack is the most dramatic single incident of 2026 but it is not an isolated event. Blockaid found that most crypto losses in the first half of 2026 came from compromised keys and operational mistakes — exactly the category this attack falls into.

The attack exposed a specific tension that sits at the heart of self-custody crypto: keeping your key where no hacker can reach it and creating a key no computer can guess are two separate problems. The Coldcard attack solved the first problem perfectly. Every drained wallet stayed offline throughout. It failed at the second problem entirely.

For holders who do not want that responsibility, regulated custodians and spot Bitcoin ETFs offer an alternative — trading the specific risks of self-custody for institutional-grade security infrastructure, insurance, and regulatory oversight. Bitcoin ETFs managed by institutions including BlackRock hold more than 773,000 Bitcoin under custody arrangements that involve multiple layers of security auditing, insurance, and regulatory compliance. The tradeoff is counterparty trust rather than personal security responsibility.

Neither option is without risk. But the Coldcard attack makes clear that self-custody risk is not zero, and that the complexity of managing cryptographic security correctly is higher than most retail holders fully appreciate.

What This Means for the Broader Market

Bitcoin’s price fell sharply in the immediate aftermath of the attack as the scale of the losses became clear. It has partially recovered as the crypto community has absorbed the distinction between a firmware flaw in one wallet manufacturer and any fundamental problem with Bitcoin itself.

The market’s eventual recovery reflects a genuine and important distinction. The Coldcard attack is a story about one company’s implementation failure, not about Bitcoin’s underlying security. The blockchain did not fail. The cryptography underlying Bitcoin did not fail. A hardware manufacturer’s random-number generator failed.

That distinction matters for the long-term investment case. But it does not eliminate the practical security question that every Bitcoin holder now has to answer: how confident are you in the specific custody arrangement protecting your digital assets?

A Note on Physical Gold

In a week dominated by stories about digital asset security failures — from OpenAI’s AI going rogue and hacking an outside company to Coldcard’s firmware flaw enabling the theft of $110 million in Bitcoin — it is worth a brief observation about a very different kind of asset.

Physical gold cannot be hacked. There is no firmware to exploit. No random-number generator to compromise. No seed phrase to reconstruct from a serial number. An ounce of gold sitting in an insured, audited depository under your account’s name requires a physical act to move — and every movement is logged, audited, and insured.

That is not an argument against Bitcoin or digital assets. It is simply a statement about a different category of risk. The week’s events are a useful reminder that real assets and digital assets carry fundamentally different security profiles — and that a retirement portfolio built entirely on one category of risk, whether digital or paper, has concentrated exposure that a genuinely diversified approach would not.


Sources:

Related Posts

Wealth Preservation Guide

Request Your FREE
Wealth Preservation Guide

Before You Go...

Request Your FREE Wealth Preservation Guide

WealthPreservationGuide