{
  "id": 1531501,
  "title": "Coldcard Breach Losses Now Exceed $115 Million",
  "url": "https://urgent.news/2026/08/17/coldcard-breach-losses-now-exceed-115-million",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-17T17:49:58.000Z",
  "source": {
    "name": "PYMNTS",
    "slug": "pymnts",
    "url": "https://www.pymnts.com/cryptocurrency/2026/coldcard-breach-losses-now-exceed-115-million/"
  },
  "original_language": "en",
  "account": "Coldcard hardware wallets have suffered losses exceeding $115 million due to a security breach, as reported by Galaxy Research. The company spoke with over 200 victims to gather intelligence on the attackers. The incident occurred through a vulnerability in older firmware versions used by Coldcard, a popular bitcoin hardware wallet from Coinkite. The five-year-old flaw was undetected until it was too late, compromising the randomness used to create recovery phrases for some wallets. This weakened the private keys derived from them, making it easier for attackers to drain Bitcoin from thousands of users.\n\nTwenty-One Million, a company providing crypto-related trackers and calculation tools, established a page to keep updated on the incident. They noted that some trackers place losses at over $130 million. Both Coinkite and TRM Labs have created pages to provide updates on the theft. The company emphasized that weak randomness has targeted bitcoin wallets before, citing past incidents like the 2023 \"Milk Sad\" bug and the 2022 Wintermute hack. These instances of \"predictable randomness\" were eventually discovered in public code, highlighting the importance of open-source, auditable hardware. However, Twenty-One Million stressed that open-source doesn't replace additional protections like dice rolls, passphrases, or real multisig.\n\nPYMNTS wrote earlier this month that the Coldcard failure highlights the risk of treating offline storage as the final solution to security concerns. They explained that an offline device can still generate a vulnerable key, and even with open-source software, flaws can exist. The wallet incident emphasizes that critical security questions are outside the blockchain and in hardware, software, governance, and operational controls determining who can generate a valid signature. The Coldcard crypto incident is part of a series of crypto-related thefts in 2026, with losses reaching around $972 million in the first seven months, according to a recent CoinDesk report.",
  "summary": "Losses from a recent security incident involving Coldcard hardware wallets have now surpassed $115 million. That’s according to Galaxy Research, which posted those calculations on X Sunday (Aug. 16), saying they were based on its data through Aug. 13. The company added it has spoken with more than 200 victims “to support them and gather intelligence on the attackers.” […] The post Coldcard Breach…",
  "key_points": [
    "Coldcard hardware wallets lost $115 million due to security breach",
    "Vulnerability in older firmware versions compromised wallet security",
    "Weak randomness in recovery phrases made private keys easier to steal"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}