Skip to main content

Hackers steal over $130 million by exploiting bug in offline hardware wallets

Crypto thieves have stolen roughly $130 million from Coldcard hardware wallet users by exploiting a predictability flaw in seed phrase generation.

AI-written
Inewgen
05 Aug 2026Source: TechCrunch3 min read (0 views)
Share
Hackers steal over $130 million by exploiting bug in offline hardware wallets

Stock photo for illustration only, not from the actual event

Font size
  • Hackers target Coldcard hardware wallets, stealing over $130 million in crypto.
  • A flaw in a 2021 code line made user seed phrases predictable to attackers.
  • Victims lost large sums despite keeping their offline devices in secure physical safes.
  • Manufacturer Coinkite urged users to update devices and migrate to new seed phrases.

Cryptocurrency owners utilizing supposedly secure offline hardware wallets have fallen victim to a massive wave of digital theft, according to blockchain security firms monitoring the incidents. At least a dozen distinct hacker groups are reportedly targeting Bitcoin holders who rely on the Coldcard hardware wallet produced by Coinkite.

Galaxy Research reported that the attackers have managed to steal approximately $130 million as of Tuesday, a figure corroborated by Tom Robinson, co-founder and chief scientist of blockchain monitoring firm Elliptic. This follows a broader trend of digital heists tracked by TRM Labs, which recorded over 200 hacks targeting crypto companies resulting in losses exceeding $950 million this year alone.

$130MStolen from Coldcard wallets
$200+Crypto company hacks this year

What makes these ongoing attacks particularly striking is the core premise of using a Coldcard wallet, which is designed to be one of the safest methods for holding cryptocurrency. Users store their secret seed phrase—the master password—on a specialized device completely disconnected from the internet, keeping the assets protected offline unlike online hot wallets.

cryptocurrency hardware wallet device

Stock photo for illustration only, not from the actual event

However, security researchers at Block discovered a critical flaw in how Coldcard wallets generated these seed phrases, rendering them predictable. Armed with knowledge of this generation flaw, hackers were able to bypass physical security measures entirely and brute-force the victims' seed phrases at scale without ever needing to breach physical safes.

Never miss the latest news?

Subscribe to get news summaries by email - not often enough to be annoying.

โฆษณา

"None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability."

Jonathan Goodman

This incident highlights a critical vulnerability paradigm in modern hardware security: physical isolation cannot protect assets if the underlying cryptographic entropy or generation code contains flaws. Even when users follow absolute best practices for physical storage, software architecture oversights can introduce fatal systematic risks.

Coinkite published a security advisory urging users to update their devices immediately and migrate their holdings to newly generated seed phrases. The company did not immediately respond to media requests for comments regarding the security breach.

Source: TechCrunch

Comments

Leave a Comment
0/2000

Found something wrong in this article? Report an issue with this article