What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin

CBC | World News · collected 2026-08-05 · by CBC
Read the original at CBC | World News ↗

Summary

A data breach involving Coldcard, a Toronto-based company's bitcoin-only hardware wallet, has stolen over $100 million worth of cryptocurrency. According to Galaxy Research, hackers have drained at least 1,596 bitcoins from around 7,300 addresses in multiple attack waves since Thursday. The breach was caused by a bug in the software that allowed hackers to reconstruct wallet "seed phrases", which are used as a digital signature to authorize transactions. Coinkite has warned users to move their funds immediately and released firmware updates for affected products.
Written by the local model on 2026-08-21, using this article's own text rather than the other coverage of the same event (that is the story summary below).

Signals How these are calculated →

Claims extracted
40
claim-shaped sentences
Uncertain
22%
9 of 40 hedged
Leaning
not scored
needs a local LLM pass
Publisher trust
95.3
red-flag proxy, not a credibility rating
Outlets on this story
1
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-08-05 · how these are computed

AI analysis (generated at analysis time, not now)

Story summary

Coinkite, a Toronto-based company, created Coldcard, a hardware wallet used for storing "seed phrases" of bitcoin offline. However, hackers have exploited a flaw in the firmware of affected Coldcards, which originated in March 2021, and stolen over $100M worth of bitcoin from approximately 7,300 addresses, with some estimates suggesting the total could reach up to $130 million US if another suspected wave is verified. The hackers used a deterministic pseudo-random generator instead of the intended hardware-backed true random number generator. This has resulted in 1,596 bitcoin stolen so far, and users are advised by Coinkite to "move your funds now" as a precaution.

Written for “Coldcard Bitcoin Hack” on 2026-08-31, grounded in this article and the 0 other(s) covering the same event.
Why this leaning score
The article's tone is neutral, but some word choices and framing suggest a slightly right-leaning bias. For example, the phrase 'earned back our users' trust' implies that Coinkite bears responsibility for the hack, which may be perceived as a criticism of the company rather than a neutral statement.
Written under an earlier scoring contract, which gave a paragraph rather than checkable quotes. Re-analysing this article replaces it.
Leaning score +0.45 for article 406 · logged 2026-08-05

Story

📰 Coldcard Bitcoin Hack
Technology · 1 article(s) covering the same event. This is the one the site leads with.

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

Nothing to compare against. No article is close enough to this one for the pipeline to have linked or judged the pair.

Publisher

CBC | World News · 214 article(s) · 0 correction(s) detected
SignalValueWeight
Correction rate 0.000 0.4
Uncertainty density 0.093 0.25
Assertive mismatch rate 0.000 0.35
No corrections detected for this publisher. That may mean careful reporting, or simply that nothing has been checked.

Who wrote this

No reporter is named on this article, beyond the feed's “CBC”.

Topics

Bitcoin Coinkite Coldcard Galaxy Research Toronto

Subjects

Coinkite ORG · 6× Coldcard ORG · 5× Galaxy Research ORG · 3× Novak PERSON · 2× Toronto GPE · 2× B.C. GPE · 1× Bitcoin ORG · 1× CBC News ORG · 1× Canadians NORP · 1× Rodolfo Novak PERSON · 1×

Narrative

In an update on Sunday, Coinkite acknowledged that the exploited flaw originated in March 2021, where instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware had relied on a deterministic pseudo-random generator.
framing: mixed · carried by 1 article(s) · first seen 2026-08-05
🔮 As of Monday, an on-chain analysis by Galaxy Research said that three confirmed attack waves and a number of other "smaller incidents" have resulted in 1,596 bitcoin stolen from roughly 7,300 addresses, it said in a post on X. If a suspected fourth wave is also verified, the total could jump to some 2,055 bitcoin lost, which is worth roughly $130 million US.

Claims (40 extracted, 9 hedged)

What we know about ongoing Coldcard hack that's stolen over $100M worth of bitcoin Toronto-based company Coinkite advised its users to 'move your funds now' asserted
company → know → funds
Hackers reportedly drained more than $100 million US worth of bitcoin from Coldcard hard wallets, according to blockchain intelligence firm Galaxy Research. uncertain
Hackers → drain → Research
Here's what we know about the ongoing hack, who is affected and what you should do to secure your cryptocurrency. asserted
you → know → cryptocurrency
How Coldcard works Coldcard, created by Toronto-based company Coinkite, is also known as a hardware wallet — but it doesn't actually store any bitcoin for you. asserted
it → work → you
Bitcoin remains on the public blockchain network, but a Coldcard adds an extra layer of security by storing "seed phrases" offline — without ever needing to be connected to the Internet — inside of the physical device. asserted
Coldcard → remain → device
"Seed phrases" are a sequence of random words, meant to be difficult or impossible to guess, which act as a master key to the bitcoin-only wallet. asserted
which → mean → wallet
The seed phrases, or keys, act as a digital signature that allow a user to authorize and sign transactions, as the owner of the bitcoin. asserted
user → act → bitcoin
The wallet is marketed as "cold storage" for long-term bitcoin users who want to keep their keys offline and has been widely praised by users and security experts as one of the most secure places to store bitcoin. asserted
who → market → bitcoin
What happened On Thursday, Coinkite warned its users of a bug in the software that allowed hackers to reconstruct wallet "seed phrases." asserted
hackers → happen → phrases
That major vulnerability in its software allowed waves of attacks where hackers were able to gain access to users' bitcoin wallets, without ever needing to physically get ahold of the device. asserted
hackers → allow → device
As of Monday, an on-chain analysis by Galaxy Research said that three confirmed attack waves and a number of other "smaller incidents" have resulted in 1,596 bitcoin stolen from roughly 7,300 addresses, it said in a post on X. If a suspected fourth wave is also verified, the total could jump to some 2,055 bitcoin lost, which is worth roughly $130 million US. uncertain
which → say → bitcoin
Federal government plans to ban crypto ATMs to stop scammers from defrauding Canadians Waterboarding, sexual assault, disguises: Details of terrifying $2M B.C. bitcoin hostage-taking revealed Rodolfo Novak, the co-founder and CEO of Coinkite, advised anyone who has generated a seed using a Coldcard wallet, to "move your funds now," after releasing firmware updates for affected product, according to an advisory on its website. uncertain
who → plan → website
"We know an apology doesn't return anyone's funds. asserted
apology → know → funds
We know we'll have to earn back our users' trust," Novak said in a post on X on Friday. asserted
Novak → know → Friday
CBC News has reached out to Coinkite but did not immediately hear back. asserted
News → reach → Coinkite
In an update on Sunday, Coinkite acknowledged that the exploited flaw originated in March 2021, where instead of generating wallet seeds through the intended hardware-backed true random number generator, affected firmware had relied on a deterministic pseudo-random generator. asserted
firmware → acknowledge → generator
The company said it destroyed remaining inventory manufactured with the vulnerable firmware, and shipment was halted when the vulnerability was confirmed. asserted
vulnerability → say → firmware
Novak warned other developers in his statement, adding that AI is to blame. " asserted
AI → warn → statement
To every other developer: we believe this is a sober reality of the new AI paradigm. asserted
this → believe → paradigm
AI-assisted code review can now find latent bugs at a speed that is outpacing even the industry’s most seasoned experts. asserted
that → assist → experts
If your firmware is open-source or has ever been public, assume it's already being read by attackers and defenders alike. asserted
it → assume → attackers
" How users are affected All Coldcard users are at risk of their wallet potentially being accessed as a result of this software bug. asserted
wallet → affect → bug
Roughly 90 per cent of the stolen bitcoin has not moved, meaning the tokens are still sitting in the same wallets where they were sent after the reported theft, according to Galaxy Research. uncertain
they → steal → Research
That means they have not been further transferred to another wallet, sold or exchanged, according to the firm. uncertain
they → mean → firm
Bitcoin transactions, which are public on the blockchain, can be tracked down and hackers could want to wait before they move the stolen funds. uncertain
they → track → funds
Details from the ongoing investigation into the hacks, such as attacker and victim addresses, have been shared with U.S. law enforcement agencies, cryptocurrency exchanges and cyber-investigation groups, the research firm said. asserted
firm → share → agencies
"It is essential that we continue to identify additional attacker addresses, especially as new, opportunistic attackers emerge, so that we can report their addresses to authorities," Galaxy Research said. asserted
Research → continue → authorities
The attack "exposes the fallacy of your crypto being offline," said Aneirin Flynn, CEO of cybersecurity technology firm FailSafe, in an interview with Bloomberg. asserted
Flynn → expose → Bloomberg
“The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered. asserted
passwords → generate → passwords
" What you should do Don't keep your bitcoin where it is if you think your wallet may be compromised. uncertain
wallet → keep → bitcoin
Installing Coldcard's new firmware protects only wallets created after the fix, according to Coinkite, which means that existing seed phrases generated on vulnerable devices remain at risk and should be replaced. uncertain
phrases → instal → risk
The Canadian security company advised customers to install the latest update for their device. asserted
company → advise → device
"Do not generate a new seed on any of these models until the update is installed," Galaxy Research said. asserted
Research → generate → models
Coinkite added that its investigation is underway and a "formal technical review will be released as soon as possible." asserted
review → add → ?
But some experts say the harm is already been done. asserted
harm → say → ?
"The workaround for this isn't easy or intuitive to deal with," Brent Arnold, a cybersecurity lawyer and partner and data breach coach with Toronto-based INQ Law, told CBC News on Tuesday. asserted
Arnold → deal → Tuesday
"And lots of people won't have heard about this until it's too late." Affected Coldcard users have the option to move their funds elsewhere, to another company that holds the assets on the users' behalf. asserted
that → hear → behalf
"If you are using a Coldcard and unsure whether it's safe, migrate your funds to a safe address at a custodian/exchange or a fresh seed," Galaxy Research said in a post on X. Coinkite also advised its customers not to dispose of the device if it has been affected. asserted
it → use → device
"It may become essential if funds are recovered. uncertain
funds → become → ?
Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible," it said. asserted
it → coordinate → those
💬 Give feedback
🕘 History 🎫 Support