Cryptocurrency3 mins read

Coldcard Hardware Wallet Bug Linked to Over $130M in Crypto Thefts

Hackers are exploiting a vulnerability in Coldcard offline hardware wallets, with blockchain-monitoring firms estimating losses at more than $130 million.

Bitcoin coins cryptocurrency on U.S. dollar banknotes background.
Image credits:alexsl / Getty Images

What happened

Hackers are stealing cryptocurrency from Coldcard hardware wallet users, according to blockchain security firms monitoring the activity. TechCrunch reports that losses are estimated at more than $130 million, with Elliptic’s Tom Robinson saying the estimate is roughly correct. At least a dozen different hackers are said to be targeting Bitcoin owners who use Coldcard, and it remains unclear who is behind the thefts.

Why offline wallets were still exposed

Coldcard is designed as a “cold” wallet, meaning the device is not connected to the internet and stores the secret key or seed phrase offline. The reported weakness was not that hackers broke into an online account, but that a flaw made some generated seed phrases predictable. According to security researchers at Block, attackers could brute-force and generate victims’ seed phrases once they understood the flaw.

Why the scale matters

The incident stands out because cold wallets are often considered one of the safer ways to store cryptocurrency. TechCrunch notes that crypto hacks have already been widespread this year: TRM Labs reported more than 200 hacks targeting cryptocurrency companies, with total losses above $950 million. This case shows that offline storage can still fail if the device’s seed-generation process is flawed.

What users should take away

Coinkite published an advisory alerting users to the flaw and urged them to update their devices and migrate to a new seed phrase. For wallet owners, the key takeaway is to treat vendor security advisories as urgent, especially when seed phrase generation is involved. If a wallet’s original seed phrase may be affected, updating alone may not be enough without moving funds to a newly generated seed phrase.

Discover More

    Cybersecurity-themed illustration used for a report on AI-generated exploit scripts targeting industrial control systems
    AI speeds ICS attacks

    U.S. agencies warn AI-generated exploit scripts are raising risks for exposed Siemens S7 industrial controllers.

    CybersecurityIndustrial Control Systems
    A T-Mobile store in Times Square with bright pink T-Mobile signage.
    T-Mobile Cut Off Hackers

    T-Mobile reportedly stopped Salt Typhoon activity by physically severing a compromised system’s connection.

    CybersecurityT-Mobile