
The biggest cold wallet hacks in crypto history, ranked from Bybit to the 2026 Coldcard exploit. Learn how each one failed and how to protect your keys.
Author: Kritika Gupta
The biggest cold wallet hacks in crypto history prove that offline storage does not eliminate every security risk. Attackers have stolen or frozen billions of dollars by compromising validator keys, manipulating signing interfaces, exploiting weak firmware, and targeting poorly managed wallet infrastructure.
From the $1.5 billion Bybit breach and the collapse of Mt. Gox to the 2026 Coldcard exploit, each incident exposed a different weakness in self-custody. This article examines the largest cold wallet failures, explains how the attacks happened, and highlights the practical steps investors can take to protect their crypto holdings.
On July 30, 2026, an attacker drained 594 BTC worth approximately $38 million from nearly 500 Coldcard hardware wallets in just 25 minutes. By August 2, three coordinated attack waves had pushed the total loss to roughly $89 million across 4,585 addresses. The attacker did not rely on phishing, malware, or stolen exchange credentials. Instead, a firmware flaw had allegedly weakened Coldcard’s random number generation for five years, allowing predictable seed phrases to be reconstructed offline.
The incident delivers a stark warning for Bitcoin self-custody: keeping private keys offline does not guarantee safety when the wallet generates those keys insecurely. From Coldcard’s firmware failure to Bybit’s manipulated signing interface, Ronin’s stolen validator keys, and Mt. Gox’s operational collapse, the biggest cold wallet hacks in crypto history show that cold storage remains only as secure as the software, devices, and people surrounding it.
As a result, the breach challenges one of Bitcoin’s most widely accepted security assumptions. Self-custody promises protection because users control their own keys and keep them offline. But what happens when the wallet creates predictable keys from the beginning? If Coldcard’s key-generation process could remain vulnerable for years, users must question whether hardware ownership alone can guarantee security.
Against this backdrop, this article examines the biggest cold wallet failures in crypto history, from compromised multisig systems and stolen validator keys to broken firmware and weak operational controls. Although the Coldcard exploit is the newest case, it may also be the most unsettling because it shows that even an offline wallet can fail before a user makes their first transaction.
A cold wallet stores private keys offline and keeps them isolated from the internet. Commonly, cold-storage methods include hardware wallets such as Coldcard, Ledger, and Trezor, as well as air-gapped computers, paper wallets, and multisig setups that require multiple approvals before funds can move.
In principle, the security premise is simple: when private keys never touch the internet, remote attackers cannot access them. However, cold storage only protects users when secure software and operational processes generate, store, and use those keys. For example, if a device creates a weak seed, as Coldcard allegedly did, or attackers manipulate the signing process, as seen in the Bybit hack, keeping the wallet offline does not prevent a loss. Ultimately, offline storage is only as secure as the technology and procedures surrounding it.
Largest Cold Storage and Multisig Crypto Incidents

On February 21, 2025, attackers drained approximately 400,000 ETH, worth about $1.5 billion, from Bybit’s Ethereum multisig cold wallet. The theft occurred during a routine transfer from cold storage to the exchange’s hot wallet, making it the largest crypto hack on record.
The attackers did not steal Bybit’s private keys directly. Instead, they manipulated the signing interface so that it displayed the correct destination address while secretly changing the underlying smart contract logic. As a result, Bybit’s signers believed they were approving a standard transfer, but the transaction redirected the funds to attacker-controlled wallets.
Following the breach, investigators traced the attack to a compromised SafeWallet developer’s machine. The attackers injected malicious JavaScript into SafeWallet’s AWS infrastructure and designed the code to activate only when Bybit’s signers accessed the interface. Consequently, the malicious changes remained difficult to detect until the transfer had already received approval.
Meanwhile, Elliptic, Arkham, ZachXBT, and Mandiant linked the attack to North Korea’s Lazarus Group. Despite the scale of the loss, Bybit said it remained solvent and covered the shortfall. To reassure users, the exchange issued a direct statement: “We are solvent.”
Ultimately, the Bybit hack exposed a critical weakness in institutional cold storage. Even a multisig wallet with strict approval controls can fail when attackers compromise the software supply chain surrounding the signing process. In this case, Bybit’s keys remained secure, but the interface instructing signers how to use those keys did not.

On March 23, 2022, attackers compromised five of the nine validator keys securing the Ronin bridge, which supported the Axie Infinity ecosystem. They used the stolen keys to withdraw 173,600 ETH and 25.5 million USDC, worth approximately $624 million at the time. However, the Ronin team did not discover the theft until six days later.
The attackers gained access through a targeted social engineering campaign. They sent a fake job offer to a Sky Mavis employee and delivered a trojan through a PDF disguised as part of the recruitment process. After the employee downloaded the file, the attackers entered the company’s internal systems and obtained enough validator keys to approve the fraudulent withdrawals. The U.S. Treasury later attributed the attack to North Korea’s Lazarus Group.
The Ronin hack showed that multisig security depends on more than the number of required signatures. A system can use several validator keys and still fail when attackers compromise enough key holders through one weak access point. Therefore, teams must secure every signer, device, and internal process because a single successful social engineering attack can undermine the entire approval threshold.

Between 2011 and 2014, attackers stole approximately 850,000 BTC from Mt. Gox, which operated as the world’s largest Bitcoin exchange at the time. The theft continued gradually for years before the exchange discovered the losses in February 2014. At the time of disclosure, the missing Bitcoin carried a value of roughly $470 million.
Mt. Gox suffered from catastrophic internal security failures. The exchange failed to separate hot and cold wallet keys, conduct regular audits, or enforce clear responsibilities among employees. In addition, it stored critical keys on the same systems that supported daily exchange operations. As a result, attackers could access wallets that the company described as cold storage.
The losses ultimately forced Mt. Gox to collapse, while authorities later arrested CEO Mark Karpeles. Creditor repayments only began in 2024, nearly a decade after the exchange failed. Mt. Gox delivered an early warning for the crypto industry: cold storage without strict operational security is only a label. The exchange called its wallets cold but managed them like a checking account.

Among the biggest cold wallet hacks, the CoinCheck breach stands out because the exchange never implemented the cold-storage protections it needed. In January 2018, attackers stole approximately 523 million NEM tokens worth about $530 million from CoinCheck. The exchange had stored the assets in a hot wallet, even though it should have moved them into cold storage. After the breach, CoinCheck admitted that it lacked the technology and staff required to implement proper offline storage.
Unlike other major wallet breaches, attackers did not need to compromise cold-storage infrastructure because CoinCheck had never deployed it. Therefore, the incident exposed a basic design failure rather than a sophisticated technical exploit. The lesson remains simple: the most dangerous cold wallet is the one that does not exist.

The Coldcard Hack cannot be missed when talking about biggest cold wallet hacks. The Coldcard vulnerability began with a firmware change introduced in March 2021. A developer replaced ckcc.rng_bytes, which called the device’s hardware random number generator, with ngu.random.bytes, a software-based pseudorandom number generator. As a result, affected devices generated seed phrases with predictable entropy instead of drawing enough randomness directly from the hardware.
The bug affected Coldcard Mk2 and Mk3 devices running firmware versions from v4.0.0 through v5.0.3. Meanwhile, researchers found that Mk4, Q, and Mk5 devices could generate seeds with roughly 72 bits of entropy instead of the expected 128 bits. However, investigators have not confirmed that attackers exploited those later models. Instead, the confirmed losses primarily involved wallets created on the most vulnerable firmware and hardware combinations.
Once the attacker identified the weakness, they reproduced possible seed phrases offline, derived the corresponding wallet addresses, and compared them with activity on the Bitcoin blockchain. Afterward, they targeted the highest-value wallets first and swept funds through coordinated attack waves. During the first wave on July 30, the attacker moved 594 BTC in just 25 minutes. Later that day, a second wave moved another 1,082 BTC in 41 minutes. By the third wave, the incident had reached a cumulative 1,367 BTC across 4,585 addresses, worth roughly $89 million.
In response, Coinkite released patched firmware and urged affected users to generate entirely new seeds before moving their funds. Importantly, installing the update could not repair an existing weak seed because the vulnerability affected the key at the moment of creation. Therefore, users had to create a new wallet using secure randomness and migrate their Bitcoin. In addition, Galaxy Research reported approximately 600 suspected attacker addresses to investigators.
More broadly, the Coldcard exploit exposes two separate requirements for secure self-custody. Users must control their private keys, but they must also ensure that those keys were generated through secure and genuinely random processes. Historically, hardware wallet marketing has focused more heavily on ownership and offline storage than on entropy generation. As a result, Coldcard now joins Milk Sad in 2023 and Ill Bloom in 2026 as the third major pseudorandom number generator failure in recent crypto history. Ultimately, this pattern reveals a recurring weakness that the industry can no longer dismiss as an isolated bug.
Among the biggest cold wallet hacks, the Parity incident stands out because attackers did not steal the funds. In November 2017, a developer accidentally called the kill function on the library contract that governed Parity’s multisig wallets. The action permanently froze approximately 513,000 ETH, worth about $280 million at the time. Instead, the contract locked the funds and left wallet owners unable to recover their assets.

The Parity incident showed that smart contract bugs in cold wallet infrastructure can cause as much damage as a direct theft. Even when private keys remain secure, a flaw in the code controlling the wallet can make the funds inaccessible forever.

Earlier, in August 2016, attackers compromised the multisig arrangement between Bitfinex and BitGo. They stole approximately 120,000 BTC, worth around $72 million at the time. In 2022, the U.S. Department of Justice recovered roughly 94,000 BTC and arrested Ilya Lichtenstein in connection with laundering the stolen funds.
Therefore, the Bitfinex hack demonstrated that third-party co-signers do not automatically guarantee multisig security. A multisig setup only works when every signer, integration, and approval process remains secure.
Although each breach used a different method, the largest cold wallet failures follow five recurring attack patterns:
More importantly, the biggest cold wallet hacks show that attackers rarely need to break the underlying cryptography. Instead, they target the people, software, devices, and operational processes surrounding private keys. A wallet can remain offline while a compromised signer, weak seed, vulnerable contract, or poorly managed key still exposes the funds.
Blockaid’s H1 2026 security report reinforced this conclusion. According to the report, compromised keys and operational security failures caused most crypto losses during the period, while pure smart contract attacks accounted for a smaller share. The Coldcard exploit fits this pattern because the attacker did not crack Bitcoin or bypass offline storage. Instead, they exploited predictable keys that vulnerable firmware had generated years earlier.
Cold Wallet Failure Types and Security Protections
The biggest cold wallet hacks show that offline storage alone cannot eliminate every security risk. Start by adding a strong BIP-39 passphrase to your wallet. The passphrase creates an additional layer of protection beyond the recovery seed. Even if vulnerable firmware generated a seed with weak entropy, a long and unique passphrase can make it significantly harder for an attacker to access the wallet. Coinkite also confirmed this as an important mitigation.
Next, generate seeds on more than one independent device and compare the results. Two properly functioning hardware wallets should never produce the same recovery seed. If they do, stop using both devices immediately because the result indicates a catastrophic failure in the seed-generation process.
You should also keep your wallet firmware updated. The Coldcard vulnerability remained in firmware released as far back as 2021. Although an update cannot repair an existing weak seed, patched firmware can prevent the device from generating vulnerable seeds in the future. Therefore, users with affected wallets must create a new seed on secure firmware and transfer their funds to the new addresses.
For larger holdings, use multisig with hardware wallets from different manufacturers. For example, a 2-of-3 setup that combines Coldcard, Trezor, and Ledger reduces the risk that a bug affecting one vendor can compromise the entire wallet. However, multisig still requires secure signers, interfaces, backups, and approval procedures.
In addition, simulate transactions before signing them. Transaction simulation tools show what a transaction will actually do on-chain rather than relying only on the information displayed by a wallet interface. This extra check could expose manipulated contract logic like the technique attackers used during the Bybit hack.
Finally, verify security claims instead of trusting them blindly. Open-source firmware allows independent researchers to review the code, while closed-source firmware requires users to place greater trust in the manufacturer. Ethereum and DeFi users should also review token permissions through Revoke.cash each month and remove approvals they no longer need.
Cold storage is still the safest option for long-term crypto holdings. However, safe does not mean infallible. Treat your security setup like software: it needs updates, audits, and vigilance.