Coldcard Flaw Exposes $130 Million in 'Cold Storage' Theft

AI-generated image · Bay Street Wire
Hackers bypassed offline security by exploiting a seed phrase generation bug in Coinkite's hardware wallets.
A critical vulnerability in Coldcard hardware wallets, produced by Coinkite, has allowed hackers to steal approximately $130 million in cryptocurrency, according to reporting from TechCrunch.
While Coldcard devices are designed as "cold" wallets—keeping secret keys offline to protect assets on the blockchain—security researchers at Block discovered a flaw in how the devices generated seed phrases. This vulnerability made the phrases predictable, allowing at least a dozen different hackers to brute-force and generate the keys at scale. Because the flaw existed in the original code from 2021, the theft occurred regardless of whether users kept their devices in safety deposit boxes or offline.
Jonathan Goodman, a victim who claimed hackers stole $1.6 million from his wallet, stated on X that he never shared his seed phrase and his devices never touched the internet, yet the vulnerability rendered those precautions irrelevant.
Galaxy Research noted that multiple groups of hackers appear to be involved in the robberies, a figure corroborated by Tom Robinson, co-founder and chief scientist at Elliptic. This breach contributes to a broader trend of insecurity in the sector; TRM Labs reports that more than 200 hacks have targeted cryptocurrency companies this year, resulting in losses exceeding $950 million.
Coinkite issued an advisory on Thursday, updated Saturday, notifying users of the flaw and urging them to update their hardware and migrate to new seed phrases. Coinkite did not respond to TechCrunch's request for comment.

