Hackers have stolen approximately $130 million in cryptocurrency from owners of Coldcard hardware wallets by exploiting a flaw in how the devices generated seed phrases, according to blockchain security firms monitoring the thefts. The heists were ongoing as of Tuesday, August 4, 2026.
At least a dozen hackers or hacker groups are believed to be targeting users of Coldcard, a hardware crypto wallet made by Canadian company Coinkite. Security researchers at Block identified the core vulnerability: the wallets generated seed phrases — the secret keys used to access stored cryptocurrency — in a predictable way. That predictability allowed hackers to brute-force and replicate victims’ seed phrases without ever physically accessing their devices.
Coldcard wallets are designed to store seed phrases offline, disconnected from the internet, making them a popular choice among Bitcoin holders seeking to avoid the risks associated with internet-connected “hot” wallets. The flaw undermined that protection entirely. According to Galaxy Research, the vulnerability traces back to a single line of code introduced in 2021.
“Perhaps the hardest part about this is that I did everything right,” wrote Jonathan Goodman on X, claiming $1.6 million was taken from his Coldcard wallet. “I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes. None of it mattered.”
Coinkite published an advisory alerting users to the flaw and urging them to update their devices and migrate to a new seed phrase. The company did not respond to a request for comment.
The theft adds to a broader pattern of cryptocurrency losses in 2026. Blockchain-monitoring firm TRM Labs reported more than 200 hacks targeting cryptocurrency companies this year, with total losses exceeding $950 million. The Coldcard incident suggests that even offline storage solutions may carry significant risk if underlying hardware or software contains undetected vulnerabilities.
Source: TechCrunch