VMTech
Discuss a project

Coldcard seed-generation flaw exposes Bitcoin owners to $130 million theft

Coldcard seed-generation flaw exposes Bitcoin owners to $130 million theft

At least a dozen hackers are targeting Bitcoin owners who use Coinkite's Coldcard hardware wallets, with roughly $130 million stolen as of Tuesday, Galaxy Research said. Elliptic co-founder and chief scientist Tom Robinson told TechCrunch that the estimate was roughly correct.

The identities of those responsible remain unclear. Galaxy Research believes more than one group is involved, making the continuing operation a broad campaign rather than an incident attributed to a single attacker.

Why an offline wallet was still vulnerable

Coldcard is designed to keep a Bitcoin owner's secret key or seed phrase on a device that is not connected to the internet. The Bitcoin remains on the blockchain, but the credential needed to control it lives offline. This is known as a cold wallet, unlike hot wallets in apps, browser extensions, or accounts on exchanges such as Binance and Coinbase.

That separation is intended to reduce exposure to online attacks. In this case, however, researchers at Block found a flaw in the way Coldcard wallets generated seed phrases. The phrases were predictable, allowing attackers to brute-force victims' credentials without compromising the offline devices themselves.

The change from reported $70.2 million Coldcard outflow to the current estimate shows the growing scale reported by investigators, while the underlying weakness remains in seed generation rather than internet connectivity.

In practical terms, the attackers did not have to open the safe holding a device or steal a written recovery phrase. Once they understood how vulnerable phrases had been produced, they could generate the keys at scale and use them to move the associated Bitcoin.

Physical safeguards did not address the code flaw

Jonathan Goodman said $1.6 million was stolen from a Coldcard wallet despite never sharing the seed phrase, never connecting the devices to the internet, and storing materials in multiple safes and safety deposit boxes. Goodman attributed the loss to a vulnerable line of code dating from 2021.

The episode demonstrates why physical isolation alone could not protect affected owners. The secret did not need to leak from storage if its creation process made it possible to reconstruct.

Coinkite advises an update and migration

Coinkite disclosed the flaw in an advisory published on Thursday and updated on Saturday. The company urged users to update their devices and then migrate to a new seed phrase. Coinkite did not immediately respond to TechCrunch's request for comment.

The campaign forms part of a wider rise in cryptocurrency theft. TRM Labs has recorded more than 200 hacks targeting cryptocurrency companies this year, with combined losses exceeding $950 million.

For businesses holding Bitcoin, the immediate implication is operational: follow Coinkite's advisory, update affected hardware, move assets to a newly generated seed phrase, and ensure the old credential is no longer used. Offline storage should be assessed alongside the integrity of the software that creates its keys.

#coldcard#bitcoinsecurity#cryptowallets#cybersecurity
Open analytics
On the site 0 views
min read 3 05.08.2026
Instagram

Coldcard seed-generation flaw exposes Bitcoin owners to $130 million theft

Open the post on Instagram ↗