Bitcoin worth more than $100 million has allegedly been stolen from devices known as cold wallets, in a breach that has shaken one of the assumptions at the heart of cryptocurrency. The devices in question are Coldcards, made by the Canadian company Coinkite and sold as a way to keep Bitcoin secure physically instead of on the internet. Thieves apparently found a five-year-old universal weakness in the cold card, and used it to drain the accounts of thousands of people who believed their holdings were locked safely away.
The appeal of a device like the cold card was precisely that it kept a user's Bitcoin offline. Rather than trusting an exchange or leaving funds exposed on the internet, owners could store their keys themselves on a piece of hardware, in what the industry calls cold storage. For years that approach was marketed and widely understood as the safest thing a Bitcoin holder could possibly do, which is part of what makes the current losses so jarring for the people affected.
According to the account of the breach, attackers were able to reverse engineer the cold card and figure out a flaw that had existed for about five years. Once they understood it, they could get access to the wallets and drain individuals' Bitcoin accounts. The weakness was described as universal, meaning it was not a matter of one careless user or a single stolen device but something built into how the product worked, sitting unnoticed the entire time the cold card was being trusted.
Coinkite has acknowledged the damage. In an online post, the company wrote that users have suffered real losses, and it suggested that users move their crypto off affected cold cards. That guidance amounts to an admission that devices sold as a secure vault could no longer be relied upon, and a plea for remaining holders to get their funds out before they too are targeted.
Beyond the dollar figures, the episode strikes at the core of the Bitcoin ethos, the idea that a person can store these keys themselves securely without relying on anyone else. The cold card was trusted precisely because it promised that independence. As one observer put it, the troubling part is not only that this should not have happened, but that the people who lost money did nothing wrong; they followed the advice they had been given and still saw their savings disappear.
For victims, the path to getting their money back looks narrow. It is not clear who the hackers are or where they are operating from, and those who lost funds may not be able to recover much from the company that made the device. The point was made bluntly that a buyer cannot sue the maker and win more than they paid for the hardware, and the device itself is worth at most a couple of hundred dollars, a trivial sum next to the fortunes that were drained through it.
There is also speculation that this represents a new type of attack, coming at a moment when artificial intelligence is stronger than it has ever been and is being used by both attackers and defenders alike to hunt for vulnerabilities across all kinds of companies. Some victims have said they reported their losses to authorities as theft, but even that step offers little certainty. For now it remains very unclear whether anything can be done to trace the stolen Bitcoin or hold anyone responsible.
