Tuesday, 4 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 4 August 2026 at 19:51

Hackers drain over $130 million from 'cold' crypto wallets by exploiting seed phrase flaw

Blockchain security firms are tracking a wave of attacks against Coldcard hardware wallets that has resulted in around $130 million in stolen cryptocurrency. Hackers exploited a vulnerability that made users' seed phrases predictable.

Foto: TechCrunch

Blockchain security firms are tracking a large-scale cryptocurrency theft targeting owners of supposedly secure offline hardware wallets. The attacks focus on Bitcoin users of the Coldcard device made by Coinkite. According to research firm Galaxy Research, the stolen amount stood at about $130 million as of Tuesday, and Elliptic co-founder Tom Robinson told TechCrunch that the estimate is roughly accurate.

The culprits remain unidentified, but Galaxy Research believes multiple hacker groups are involved. Security researchers at Block found that the flaw was in how Coldcard generated users' seed phrases — the codes were predictable. The attackers could then use brute force to recreate the secret phrases without ever having physical access to the devices. In effect, they found a way to duplicate keys at scale.

Coldcard wallets are designed to keep private keys completely offline, offering protection against remote hacking. This incident, however, demonstrates that such hardware is only as safe as the code used to create the keys.

Jonathan Goodman, who says $1.6 million was stolen from his Coldcard wallet, wrote on X that he never shared his seed phrase, never connected the device to the internet, and stored everything in safes and safety deposit boxes. Despite this, his funds were taken. He blamed a single vulnerable line of code in the hardware from 2021.

Coinkite published an advisory on Thursday and updated it on Saturday, urging users to update their devices and migrate to a new seed phrase. The company did not immediately respond to a request for comment.

TRM Labs data shows that more than 200 attacks against cryptocurrency companies have taken place this year, with total losses exceeding $950 million.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category