via TechCrunch
Hackers Exploit Hardware Wallet Flaw, Steal Over $130 Million in Bitcoin
Hackers are currently orchestrating a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the attacks.
At least a dozen distinct hackers are reportedly targeting Bitcoin owners who use the Coldcard hardware wallet, manufactured by Coinkite. The identities behind these digital robberies remain unclear, and evidence suggests multiple groups are involved, according to Galaxy Research.
As of Tuesday, the research firm estimated that the hackers have stolen approximately $130 million. Tom Robinson, co-founder and chief scientist at crypto monitoring firm Elliptic, told TechCrunch that this figure is roughly accurate.
This incident represents the latest in a series of large-scale cryptocurrency thefts. So far in 2026, blockchain monitoring firm TRM Labs reports over 200 hacks targeting cryptocurrency companies, with total losses exceeding $950 million.
What makes the ongoing attacks against Coldcard wallet owners particularly notable is that such products are designed to be one of the safest methods for storing cryptocurrency, at least in theory.
Bitcoin holders can store the secret key or seed phrase—essentially a password—on a Coldcard device, which is not connected to the internet. While Bitcoins themselves reside on the blockchain, they are protected by a password that exists exclusively offline. This setup is known as a "cold" wallet, in contrast to "hot" wallets, which are online, such as those in apps, browser extensions, or accounts on commercial exchanges like Binance or Coinbase.
However, hackers discovered a flaw in how Coldcard wallets generated users' seed phrases, which were predictable, according to security researchers at Block. Once this flaw was identified, attackers simply needed to brute-force and generate the victims' seed phrases.
By understanding how to create the keys, the hackers bypassed the need to physically access the devices—essentially figuring out how to cut keys at scale.
"Perhaps the hardest part about this is that I did everything right," Jonathan Goodman, who claimed to have had $1.6 million stolen from their Coldcard wallet, wrote on X. "I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes," he said.
"None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability," wrote Goodman.
In an advisory published on Thursday and updated on Saturday, Coinkite alerted users to the flaw, urged them to update their devices, and is working on patching the issue. However, given that the vulnerability stems from firmware code dating back to 2021, many users may have already been affected, and the full extent of the theft is still being assessed.
