Crypto security firms report a massive theft from Coldcard hardware wallets, exposing a flaw that allowed attackers to brute‑force seed phrases.

Hackers have siphoned more than $130 million from users of the Coldcard offline hardware wallet by exploiting a previously unknown vulnerability that allowed them to brute‑force seed phrases.

How the Exploit Worked

The flaw resides in the wallet’s firmware handling of passphrase input when the device is in offline mode. By sending a crafted series of inputs, attackers could trigger a timing side‑channel that revealed bits of the underlying seed, enabling a brute‑force attack that bypassed the wallet’s usual security measures.

Scope of the Theft

Security analysts at several crypto‑security firms estimate that the compromised wallets belonged to high‑net‑worth individuals and institutional investors, with total losses exceeding $130 million. The stolen funds have been moved through a series of mixers before landing on exchanges known for lax KYC procedures.

Response from Coldcard and the Community

Coldcard’s manufacturer, Coinkite, issued an emergency firmware update that patches the vulnerability and advises users to immediately upgrade. The company also recommends users generate new seed phrases and transfer assets to fresh devices as a precaution.

  • Update to the latest firmware released on August 3, 2026
  • Generate a new seed phrase on a clean device
  • Move funds to a newly initialized wallet
  • Enable multi‑signature safeguards where possible

Implications for Hardware Wallet Security

The incident underscores that even air‑gapped devices are not immune to sophisticated attacks. Experts warn that reliance on offline storage alone is insufficient without regular security audits and prompt patch management.

“This breach is a stark reminder that hardware wallets must be treated as software as well as a physical device,” said a senior analyst at a leading blockchain security firm.

Users are urged to stay vigilant, monitor their balances, and report any suspicious activity to their wallet providers.

TechCrunch coverage of the Coldcard wallet breach