source avatarShawn

Share

Many people have been talking about the Coldcard incident, but it’s not that cold wallets are no longer secure—simply put: Coldcard devices themselves were never directly hacked, and Bitcoin itself has no vulnerability. The issue lies in how the recovery phrases were generated. Due to a software bug dating back to 2021, some Coldcard wallets generated recovery phrases that lacked sufficient randomness. This allowed attackers to remotely guess the wallet keys by testing countless possibilities—without ever needing physical access to the device (45–50 bits of entropy instead of 180 bits). As of August 2, 2026, approximately 1,367 BTC—equivalent to nearly $89 million—has been withdrawn from over 4,500 related addresses. The key lesson here is clear: cold wallets can be extremely secure, but if the “key” is weakly generated from the start, funds can still be stolen remotely.

No.0 picture
Disclaimer: The information on this page may have been obtained from third parties and does not necessarily reflect the views or opinions of KuCoin. This content is provided for general informational purposes only, without any representation or warranty of any kind, nor shall it be construed as financial or investment advice. KuCoin shall not be liable for any errors or omissions, or for any outcomes resulting from the use of this information. Investments in digital assets can be risky. Please carefully evaluate the risks of a product and your risk tolerance based on your own financial circumstances. For more information, please refer to our Terms of Use and Risk Disclosure.