Hackers have stolen approximately $130 million in cryptocurrency by exploiting a vulnerability in Coldcard hardware wallets, devices designed to store Bitcoin offline and away from internet threats, according to a report published by TechCrunch on August 4. At least a dozen different attackers are targeting owners of the Coldcard wallet made by Coinkite, with blockchain security firms tracking the ongoing thefts. The report notes that multiple hacker groups appear to be involved in the coordinated campaign against users who believed their assets were protected by cold storage technology.
The scale of the theft was confirmed by Galaxy Research, which tracked the stolen funds through Tuesday, while Tom Robinson, co-founder and chief scientist of Elliptic, verified the estimate as "roughly correct". The incident adds to what has already been a devastating year for cryptocurrency security: blockchain-monitoring firm TRM Labs documented more than 200 hacks targeting crypto companies in 2026 so far, with combined losses exceeding $950 million. What distinguishes this attack from typical crypto heists is that it compromised hardware wallets specifically marketed as one of the safest storage methods available, devices that keep secret keys and seed phrases completely disconnected from the internet.
Security researchers at Block discovered that the vulnerability stemmed from a flaw in how Coldcard wallets generated users' seed phrases, which turned out to be predictable rather than truly random. Once hackers identified this weakness, they could brute-force generate victims' seed phrases without ever needing physical access to the devices themselves. Jonathan Goodman, who reported losing $1.6 million from his Coldcard, described his security measures on X: "I never shared my seed phrase with anybody. My devices never touched the internet." He attributed the loss to "one line in their code from 2021 that had a vulnerability." Coinkite published an advisory on Thursday, updated on Saturday, alerting users to the flaw and urging them to update their devices and migrate to new seed phrases.
The breach exposes a fundamental problem with cold wallet security: even devices never connected to the internet can fail if their underlying cryptographic generation is flawed. The report explains that hackers didn't need to break into the metaphorical safe holding the keys—they figured out how to manufacture duplicate keys at scale by reverse-engineering the predictable pattern. Because Bitcoins remain on the blockchain regardless of storage method, controlling the seed phrase grants complete access to the funds, rendering physical security measures like safes and deposit boxes irrelevant if the phrase itself is compromised. Coinkite's advisory represents the company's acknowledgment that a code vulnerability dating back to 2021 created a systemic weakness affecting an unknown number of devices manufactured and sold over multiple years.
The company's recommendation for users to migrate to new seed phrases suggests the fix addresses the generation algorithm going forward, but victims who've already been drained have no recourse for recovery since blockchain transactions are irreversible. The incident underscores cold storage's double-edged nature: while offline devices protect against online hacking vectors, they concentrate risk in the hardware manufacturer's code quality and cryptographic implementation. For an industry built on the promise of decentralized security independent of trusted intermediaries, the failure reveals how hardware wallet users must still place absolute trust in manufacturers to implement randomness correctly—a trust that, in this case, proved misplaced with catastrophic financial consequences for those who followed security best practices but were undermined by invisible code defects. Enterprises evaluating custody solutions now face the uncomfortable reality that even air-gapped systems remain vulnerable to implementation flaws invisible to end users. The concentration of losses in a single product line may accelerate calls for independent security audits and certification standards across the hardware wallet industry.

