Hackers have stolen more than $100 million US [1] worth of bitcoin after breaching Coldcard hardware wallets produced by Toronto-based company Coinkite.
This breach undermines the perceived security of "cold storage" solutions, which are designed to keep digital assets offline and safe from remote attacks.
The attackers targeted the Coldcard, a bitcoin-only hardware wallet known for its high security standards. According to reports, the hackers exploited a data breach that allowed them to recalculate private keys [3]. Once the keys were obtained, the attackers systematically drained the wallets of their holdings [3].
The total value of the stolen cryptocurrency is estimated at more than $100 million US [1], [2]. The breach affected users of the hardware wallet worldwide, regardless of their location.
Coinkite, the company headquartered in Toronto, Canada, produces the devices intended to be the safest hiding place for bitcoin [2]. However, the ability of the hackers to derive private keys suggests a fundamental failure in the encryption or seed generation process used by the devices.
Industry experts said that the scale of the theft highlights a critical vulnerability in hardware that users trust for long-term asset protection. Because the wallets were designed to be disconnected from the internet, the method used to recalculate the keys represents a significant technical escalation by the hackers [3].
“Hackers have stolen more than $100 million US worth of bitcoin.”
The breach of a hardware wallet specifically designed for high-security 'cold storage' challenges the core value proposition of offline cryptocurrency wallets. If private keys can be recalculated through a data breach, the physical isolation of the device from the internet no longer provides an absolute guarantee of safety, potentially forcing a shift in how long-term holders secure their assets.



