Coldcard hardware wallets hacked: $130M stolen via seed phrase flaw
Original: Hackers steal over $130M by exploiting bug in offline hardware wallets
Why This Matters
The breach undermines trust in offline hardware wallets, long considered the gold standard for crypto security.
Hackers have stolen over $130 million from Coldcard hardware crypto wallets by exploiting a vulnerability in how the devices generated seed phrases. At least a dozen hacker groups are targeting Bitcoin owners, with losses confirmed by blockchain firms Elliptic and Galaxy Research as of August 4, 2026.
Blockchain security firms are tracking an ongoing mass theft of cryptocurrency from Coldcard hardware wallets, manufactured by Coinkite. Galaxy Research reported that at least a dozen distinct hacker groups are involved, with total losses reaching approximately $130 million as of Tuesday. Elliptic co-founder Tom Robinson confirmed the figure is roughly accurate to TechCrunch.
The vulnerability stems from a flaw in how Coldcard wallets generated seed phrases — the secret keys used to access stored Bitcoin. Security researchers at Block determined that the generated seed phrases were predictable, allowing hackers to brute-force and recreate victims' keys without ever physically accessing the devices. A code bug dating back to 2021 is cited as the root cause.
One victim, Jonathan Goodman, posted on X that $1.6 million was stolen despite following all recommended security practices: his seed phrase was never shared, devices were never connected to the internet, and credentials were stored in multiple safes and safety deposit boxes.
Coinkite published a security advisory on Thursday, updated Saturday, urging users to update their device firmware and migrate to a new seed phrase. The company did not respond to TechCrunch's request for comment. This incident adds to a broader 2026 trend: TRM Labs reports more than 200 cryptocurrency hacks this year, totaling over $950 million in losses.