A major security flaw has shaken confidence in one of the safest ways to store Bitcoin, after hackers exploited a vulnerability in Coldcard hardware wallets to steal an estimated $89 million worth of cryptocurrency.

According to Financial Post, the attack targeted a software flaw that made some wallet recovery phrases, known as seed phrases, predictable. Security researchers estimate that more than 1,300 Bitcoin were stolen from over 4,500 wallets.

Cold wallets are widely considered one of the most secure ways to store cryptocurrency because they keep private keys offline, away from internet-connected devices. However, in this case, the weakness came from the wallet’s software rather than an online attack.

Coinkite, the Canadian company behind Coldcard, has released a software update for newly created wallets and urged affected users to generate new recovery phrases and move their funds to fresh wallets. The company is also working with law enforcement to investigate the incident.

The breach comes at a difficult time for the crypto market, with investors already facing weaker prices and heightened concerns about security.

Investor takeaway: The incident highlights that even hardware wallets are not immune to software vulnerabilities. As digital assets become more valuable, security and wallet reliability are likely to remain key priorities for both investors and crypto companies.

Disclosure: This article does not represent investment advice. The content and materials featured on this page are for educational purposes only.