Hackers steal over $130M by exploiting bug in offline hardware wallets

gurjeet1 pts0 comments

Hackers steal over $130M by exploiting bug in offline hardware wallets | TechCrunch

–:–:–:–

🚨 Flash Sale 🚨 Get $100 off your Disrupt 2026 ticket

Get $100 off your Disrupt 2026 ticket: REGISTER NOW.

Close

SearchSubmit

Site Search Toggle

Mega Menu Toggle

Topics

Latest

AI

Amazon

Apps

Biotech & Health

Climate

Cloud Computing

Commerce

Crypto

Enterprise

EVs

Fintech

Fundraising

Gadgets

Gaming

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

Social

Space

Startups

TikTok

Transportation

Venture

More from TechCrunch

Staff

Events

Startup Battlefield

StrictlyVC

Newsletters

Podcasts

Videos

Partner Content

TechCrunch Brand Studio

Crunchboard

Contact Us

Image Credits: alexsl / Getty Images

Security

Hackers steal over $130M by exploiting bug in offline hardware wallets

Lorenzo Franceschi-Bicchierai

9:27 AM PDT · August 4, 2026

Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists.

At least a dozen different hackers are said to be targeting Bitcoin owners who use the hardware crypto wallet Coldcard, made by Coinkite. At this point, it’s unclear who is behind the digital robberies, and it appears like there’s more than one group of hackers, according to Galaxy Research.

As of Tuesday, the research firm said the hackers have stolen around $130 million. Tom Robinson, the co-founder and chief scientist of crypto-monitoring firm Elliptic, told TechCrunch that the estimate is roughly correct.

This is the latest effort to steal large amounts of people’s cryptocurrency. So far this year, according to blockchain-monitoring firm TRM Labs, there have been more than 200 hacks targeting cryptocurrency companies, with a total loss of more than $950 million.

What makes the ongoing hacks against Coldcard wallet owners particularly interesting is that the point of using a product like Coldcard is that it’s supposed to be, at least in theory, one of the safer ways to store their cryptocurrency.

Bitcoin owners can store the secret key or seed phrase — essentially a password — to their cryptocurrency in a Coldcard wallet, a device that is not connected to the internet. With this system, Bitcoins are still on the blockchain, like all Bitcoins, but are protected by a password that lives exclusively offline. This is considered a “cold” wallet, as opposed to "hot" wallets that are online, such as those in apps, browser extensions, and accounts on commercial crypto exchanges like Binance or Coinbase.

As it turns out, hackers figured out that there was a flaw in how Coldcard wallets generated users’ seed phrases, which were predictable, according to security researchers at Block. Once they figured out the flaw, hackers simply needed to brute-force and generate the victims’ seed phrases.

By knowing how to make the keys, the hackers did not need to break into the safe that holds them. The hackers essentially figured out how to cut keys at scale.

“Perhaps the hardest part about this is that I did everything right,” Jonathan Goodman, who claimed to have had $1.6 million stolen from his Coldcard wallet, wrote on X. “I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes," he said.

"None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability,” wrote Goodman.

In an advisory published on Thursday and updated on Saturday, Coinkite alerted users of the flaw, urged them to update their devices, and then “migrate” to a new seed phrase.

Coinkite did not immediately respond to TechCrunch’s request for comment.

Topics

Bitcoin, blockchain, cryptocurrency, cybercrime, hackers, Security

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Lorenzo Franceschi-Bicchierai

Senior Reporter, Cybersecurity

Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.

You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.

View Bio

October 13 – 15

San Francisco

Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you.

Save up to $330 toda y!

REGISTER NOW

Most Popular

Influencers draw backlash for attending OpenAI’s first luxury trip

Dominic-Madori Davis

Sequoia’s Shaun Maguire leads $1B round for nuclear startup Valar Atomics

Julie Bort

Malaysia is reportedly shutting down Balaji Srinivasan’s Network School

Anthony Ha

YouTuber Hank Green says his AI usage is ‘not healthy’

Anthony Ha

WhatsApp is testing a new folder for...

hackers hardware techcrunch wallets cryptocurrency coldcard

Related Articles