Security

Hackers Steal Over $130 Million by Exploiting Flaw in Coldcard Hardware Wallets

At least a dozen attackers have drained bitcoin from Coldcard 'cold' wallets by exploiting predictable seed-phrase generation, blockchain security firms say. The heist highlights that offline hardware is only as safe as the code that creates its keys.

D
By Daniel Kim Security Reporter
August 4, 2026 / 7 min read

Hackers are in the middle of one of the largest thefts of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists.

The Scope

At least a dozen different hackers are targeting Bitcoin owners who use Coldcard, the hardware wallet made by Coinkite, TechCrunch reported on August 4. Galaxy Research estimates the attackers have stolen around $130 million so far; Tom Robinson, co-founder and chief scientist of crypto-monitoring firm Elliptic, told TechCrunch that estimate is roughly correct. This year has already been brutal for crypto security: TRM Labs counts more than 200 hacks targeting cryptocurrency companies, with total losses above $950 million.

How It Happened

The attack exploits how Coldcard wallets generate seed phrases. Security researchers at Block found that the generation was predictable — one line of code from 2021 introduced the flaw. Once attackers understood it, they could brute-force victims' seed phrases without ever touching their devices. "The hackers essentially figured out how to cut keys at scale," TechCrunch reported.

"Perhaps the hardest part about this is that I did everything right," said Jonathan Goodman, who claims $1.6 million was stolen from his Coldcard wallet. "I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered."

The Response

Coinkite published an advisory on Thursday, updated Saturday, urging users to update their devices and "migrate" to a new seed phrase. The breach has rattled the broader market: OKX told The Block that the exploit triggered "record" inflows to centralized exchanges, and Binance's Changpeng Zhao warned holders that "nothing is 100%" after a separate $70 million wallet exploit.

Why It Matters

Cold wallets are supposed to be the gold standard of self-custody — private keys that never touch the internet. This heist shows the weak link is not the network but the firmware: if key generation is flawed, even the most disciplined holder can be drained. The lesson for the industry is that hardware wallets need the same rigor as exchanges — independent audits, transparency, and fast disclosure.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.