Skip to content

A $116 million bitcoin theft: hackers break into one of the safest places to store cryptocurrencies

Attackers used a vulnerability in Coldcard wallets in an incident that is still ongoing and reflects a visible trend in the crypto ecosystem

A computer infected by a virus.Unplash

Forty-one minutes is all the time it took for hackers to steal millions of dollars worth of bitcoin from one of the systems considered the safest in the world to store cryptocurrency: cold wallets (a crypto wallet that does not connect to the internet and keeps user keys offline). In under an hour last Thursday, attackers used a vulnerability in a system called Coldcard and took the equivalent of $70 million. But the cybercriminals continued their attack, and so far have stolen an additional $46 million, according to data from blockchain intelligence firm Galaxy Research.

Cold wallets are considered the digital equivalent of a safe box. Because they do not connect to the internet, the risk of unauthorized access is drastically reduced. Companies, governments and individuals use this technology to protect their digital information and assets.

But the Coldcard incident has shown that not even this solution is infallible. When a user configures a wallet, the system generates a random sequence of 12 to 24 words known as a wallet seed, which is used to generate the user’s private keys to manage their funds.

The vulnerabilty dates back to a software update in 2021. Instead of creating completely random word combinations, some wallets started generating seeds in a more predictable, pattern-based way. Ferdinando Ametrano, CEO of CheckSig, explains that the attackers began trying possible combinations on a regular computer until they found the right one, then emptied the wallets without the need to install malware, use phishing techniques or physically access the devices.

The incident reflects a visible trend in the crypto ecosystem. Theft is happening through a reduced number of attacks that are large-scale and increasingly sophisticated. The best example is the attack on Bybit in early 2025. According to Chainalysis, the amount of cryptocurrency that was stolen overall that year surpassed $3.4 billion, of which the Bybit attack alone accounted for $1.5 billion.

The three biggest hacks of 2025 represented 69% of all losses registered by the sector. The thieves’ goals have also changed: personal wallets represent a growing share of stolen funds: in 2022 they were 7,3% of the total, and by 2024 they accounted for 44%.

Sign up for our weekly newsletter to get more English-language news coverage from EL PAÍS USA Edition

Archived In