Cybersecurity

Hackers steal $130 million from Coldcard wallets via seed phrase flaw

1 min read

Hackers steal $130 million from Coldcard wallets via seed phrase flaw
Photo: Kevin Horvat · Unsplash
0 0
XWhatsAppTelegramLinkedIn

Hackers have stolen more than $130 million in Bitcoin by exploiting a vulnerability in the Coldcard hardware wallet, according to blockchain security firms.

As of August 4, 2026, at least a dozen attackers in multiple groups were targeting Coldcard users, said Galaxy Research. Tom Robinson of the crypto monitoring firm Elliptic confirmed the estimate.

The theft is part of a surge: TRM Labs reported more than 200 hacks of cryptocurrency companies in 2026, causing losses above $950 million.

Coldcard is designed as an offline “cold” wallet that keeps seed phrases — passwords to cryptocurrency — disconnected from the internet, unlike “hot” wallets on exchanges such as Binance or Coinbase.

Security researchers at Block discovered that a bug in the wallet’s software made the generation of those seed phrases predictable. Hackers then brute-forced victims’ keys at scale, never needing physical access to the devices.

Jonathan Goodman, who says he lost $1.6 million, wrote on X that he kept his seed phrase in multiple safes and safety deposit boxes and never exposed the device online. He blamed a single vulnerable line of code from 2021.

In an advisory dated July 30, 2026, and updated August 1, Coinkite urged users to generate a new seed phrase after updating their devices. The company did not immediately respond to a request for comment.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.