Hackers steal over $130 million by exploiting bug in offline hardware wallets
Crypto thieves have stolen roughly $130 million from Coldcard hardware wallet users by exploiting a predictability flaw in seed phrase generation.

Stock photo for illustration only, not from the actual event
- Hackers target Coldcard hardware wallets, stealing over $130 million in crypto.
- A flaw in a 2021 code line made user seed phrases predictable to attackers.
- Victims lost large sums despite keeping their offline devices in secure physical safes.
- Manufacturer Coinkite urged users to update devices and migrate to new seed phrases.
Cryptocurrency owners utilizing supposedly secure offline hardware wallets have fallen victim to a massive wave of digital theft, according to blockchain security firms monitoring the incidents. At least a dozen distinct hacker groups are reportedly targeting Bitcoin holders who rely on the Coldcard hardware wallet produced by Coinkite.
Galaxy Research reported that the attackers have managed to steal approximately $130 million as of Tuesday, a figure corroborated by Tom Robinson, co-founder and chief scientist of blockchain monitoring firm Elliptic. This follows a broader trend of digital heists tracked by TRM Labs, which recorded over 200 hacks targeting crypto companies resulting in losses exceeding $950 million this year alone.
What makes these ongoing attacks particularly striking is the core premise of using a Coldcard wallet, which is designed to be one of the safest methods for holding cryptocurrency. Users store their secret seed phrase—the master password—on a specialized device completely disconnected from the internet, keeping the assets protected offline unlike online hot wallets.

Stock photo for illustration only, not from the actual event
However, security researchers at Block discovered a critical flaw in how Coldcard wallets generated these seed phrases, rendering them predictable. Armed with knowledge of this generation flaw, hackers were able to bypass physical security measures entirely and brute-force the victims' seed phrases at scale without ever needing to breach physical safes.
"None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability."
Jonathan Goodman
This incident highlights a critical vulnerability paradigm in modern hardware security: physical isolation cannot protect assets if the underlying cryptographic entropy or generation code contains flaws. Even when users follow absolute best practices for physical storage, software architecture oversights can introduce fatal systematic risks.
Coinkite published a security advisory urging users to update their devices immediately and migrate their holdings to newly generated seed phrases. The company did not immediately respond to media requests for comments regarding the security breach.
Source: TechCrunch
Found something wrong in this article? Report an issue with this article
Comments
Leave a Comment