Cryptocurrency3 mins read

Coldcard Hardware Wallet Bug Linked to Over $130M in Crypto Thefts

Hackers are exploiting a vulnerability in Coldcard offline hardware wallets, with blockchain-monitoring firms estimating losses at more than $130 million.

Bitcoin coins cryptocurrency on U.S. dollar banknotes background.
Image credits:alexsl / Getty Images

What happened

Hackers are stealing cryptocurrency from Coldcard hardware wallet users, according to blockchain security firms monitoring the activity. TechCrunch reports that losses are estimated at more than $130 million, with Elliptic’s Tom Robinson saying the estimate is roughly correct. At least a dozen different hackers are said to be targeting Bitcoin owners who use Coldcard, and it remains unclear who is behind the thefts.

Why offline wallets were still exposed

Coldcard is designed as a “cold” wallet, meaning the device is not connected to the internet and stores the secret key or seed phrase offline. The reported weakness was not that hackers broke into an online account, but that a flaw made some generated seed phrases predictable. According to security researchers at Block, attackers could brute-force and generate victims’ seed phrases once they understood the flaw.

Why the scale matters

The incident stands out because cold wallets are often considered one of the safer ways to store cryptocurrency. TechCrunch notes that crypto hacks have already been widespread this year: TRM Labs reported more than 200 hacks targeting cryptocurrency companies, with total losses above $950 million. This case shows that offline storage can still fail if the device’s seed-generation process is flawed.

What users should take away

Coinkite published an advisory alerting users to the flaw and urged them to update their devices and migrate to a new seed phrase. For wallet owners, the key takeaway is to treat vendor security advisories as urgent, especially when seed phrase generation is involved. If a wallet’s original seed phrase may be affected, updating alone may not be enough without moving funds to a newly generated seed phrase.

Discover More

    The Danish flag flies outside a polling station at City Hall in Copenhagen, Denmark, on March 24, 2026.
    Denmark CPR Breach

    A Danish government database breach exposed records tied to about 8 million people.

    CybersecurityData breach
    AI agents, AI swarm, agent hackers
    Armadin Raises $255.5M

    Kevin Mandia’s new agent swarm security startup is now valued at more than $2.5 billion.

    CybersecurityStartups