Crypto World

$1.6 Million Drained in a Blink: User Recounts His Dramatic Coldcard Wallet Hack

Published

on

A Canadian entrepreneur lost more than $1.6 million in Bitcoin (BTC) from a Coldcard hardware wallet in under seven minutes, part of a wave that may total 1,367.05 BTC.

The case exposes an uncomfortable truth about self-custody: doing everything right may not be enough.

How One Holder Lost 18 BTC in Seven Minutes

Cold storage means keeping private keys on a device that never touches the internet. Jonathan Goodman followed that principle carefully, storing his Coldcard in a safety deposit box.

His 18.25 BTC sat in wallets secured across multiple safes. He never shared his seed phrase and kept every device isolated from online exposure.

Advertisement

None of it mattered on July 29, 2026. Between 9:36 and 9:43 that evening, every wallet he controlled was emptied.

Follow us on X to get the latest news as it happens.

Goodman first heard about a broader problem while at his cottage.

Advertisement

Assuming it would not affect him, he checked the balances in the Wasabi wallet software and found a series of red withdrawal transactions.

The vulnerability traces back to 2021. A flaw in the code that generates seed phrases left certain devices exposed, and attackers allegedly used artificial intelligence to brute-force the affected seed phrases.

He is filing reports with the police and the Ontario Securities Commission. Recovery hopes remain slim, though he wrote that the hardest part was having done everything right.

The scale extends far beyond one victim. Galaxy Research identified three suspected attack waves targeting addresses generated by Coldcard devices.

Advertisement

Those waves involved 4,585 source addresses and drained 1,367.05 BTC, worth roughly $88.6 million at the time of reporting.

Galaxy Research estimated the observed size of the Coldcard hack is now 1,367.05 BTC across 4,585 addresses. Source: X/@glxyresearch

What Galaxy Research Found in the Attack Data

Galaxy Research head Alex Thorn indicates that the attacks appear to be ongoing. He urged users who have not moved funds from potentially vulnerable setups to act immediately.

The first two waves showed similar transaction patterns and may share a common operator, though that remains unconfirmed. The third differed significantly, suggesting either updated tools or a separate actor exploiting the same key space.

The stolen Bitcoin remains in attacker-controlled addresses, with no further movement. Drained holdings had sat dormant for an average of 3.18 years, suggesting most victims were long-term holders rather than institutions.

Galaxy stressed an important caveat. Its findings rely solely on on-chain data and have not definitively confirmed insufficient randomness in the generation of the affected addresses.

Advertisement

“…this is a blow to bitcoin self-custody and we need to do better as a community: with security, with education, and with being realistic about complexity, expectations, and recommendations we make to friends, family, and the public…,” Alex Thorn said.

Analyst Shanaka Anslem Perera highlighted a deeper irony in Coldcard’s own documentation. The manual describes its default seed-generation method as the one it trusts most, while labeling it as low risk to users.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights.

Alternatives exist within the same device. Users can combine hardware output with dice rolls, or rely on dice alone, which the manual says removes all trust in the hardware. Most users likely followed the default path. That is precisely the method Galaxy Research now links to the losses.

Advertisement

The conceptual tension runs deeper. Reproducibility, prized for verifying firmware, becomes a liability in secret generation, since both weak and strong seeds produce valid 24-word phrases that appear identical.

Devices marketed under a “Don’t Trust, Verify” ethos can still harbor entropy flaws, leaving no visible trace. Affected users should assess their setups and migrate funds where necessary.

The post $1.6 Million Drained in a Blink: User Recounts His Dramatic Coldcard Wallet Hack appeared first on BeInCrypto.

Advertisement

Source link

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version