Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Event Contracts
New
Predict price moves and seize opportunities
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
Stock CFD Derivatives
US Stocks
0 Fee
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Korean Stocks
SK Hynix
Real Korean stocks and top assets
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD Flexible US Treasury
3.8%
Earn reliable returns from treasury-backed RWAs
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
9.99%
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
Pre-IPOs
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
#Web3SecurityGuide Estimates of losses from the Coldcard hardware wallet security breach have rapidly surpassed $130 million, and the root of the problem lies in a striking detail: the issue went undetected for five years.
According to Galaxy Research's most recent tracking, losses related to Coldcard have reached 2,055 BTC, or approximately $130 million, affecting over 7,700 addresses. It's estimated that between twelve and fifteen different attackers independently exploited the same vulnerability, a figure largely confirmed by the co-founder of Elliptic in a TechCrunch interview. The attack proceeded in waves; the first wave alone withdrew 1,082 BTC from approximately 1,196 addresses in just forty-one minutes, followed by three additional waves that brought the total losses to today's level.
The technical origin of the vulnerability is truly remarkable. The problem dates back to firmware version 4.0.1, released in March 2021, which caused some devices to redirect seed generation from a hardware random number generator to a deterministic fallback mechanism using MicroPython. This means that wallets built on firmware versions 4.0.1 through 4.1.9 may have generated predictable private keys through brute-force attacks for approximately five years without being detected. This was uncovered through a joint investigation by the engineering teams of the manufacturer Coinkite and Block.
As you mentioned, this incident demonstrates extremely clearly the fact that private keys are still a single point of failure for crypto assets. In the words of the Blockaid CEO, this is the industry's "original sin," because Coldcard was designed precisely to eliminate risks specific to internet-connected devices by keeping private keys offline, but the vulnerability was hidden in the device's own key generation process. Even if most victims followed every documented security best practice, they were not protected from this root cause of the vulnerability.
Another significant side effect of the incident is that the attack itself triggered a phishing wave. Rival hardware wallet manufacturers like Trezor and Foundation reported an increase in phishing campaigns attempting to exploit the Coldcard vulnerability, with campaigns using fake "hardware audit" sites to steal victims' recovery phrases, and even bots impersonating real customer service representatives. According to TRM Labs data, approximately 76% of the value stolen in crypto hacks in the first half of 2026 stemmed from infrastructure and operational breaches, particularly private key and seed phrase theft, indicating that the Coldcard incident was not an isolated case but part of a broader trend.
This event supports a justified call for hardware wallet manufacturers to re-evaluate their software development processes, supply chain security, and user training. While open-source code and independent audits enhance security, they don't provide guarantees, as this incident demonstrates, with a regression error that went undetected for five years being the clearest evidence of this.
For users storing bitcoin in hardware wallets via Gate, the practical step is this: any Coldcard device that generated a seed in firmware versions between 4.0.1 and 4.1.9 is considered potentially compromised, and funds need to be transferred to a new wallet with a regenerated seed phrase on updated firmware; simply patching the firmware does not secure an already weak seed. During this period, it's also necessary to be cautious of any messages containing "security checks" or support requests, and under no circumstances should the recovery phrase be shared with a third party.
DYOR 🔎