Crypto security firms report a massive theft from Coldcard hardware wallets, exposing a flaw that allowed attackers to brute‑force seed phrases.
Hackers have siphoned more than $130 million from users of the Coldcard offline hardware wallet by exploiting a previously unknown vulnerability that allowed them to brute‑force seed phrases.
How the Exploit Worked
The flaw resides in the wallet’s firmware handling of passphrase input when the device is in offline mode. By sending a crafted series of inputs, attackers could trigger a timing side‑channel that revealed bits of the underlying seed, enabling a brute‑force attack that bypassed the wallet’s usual security measures.
Scope of the Theft
Security analysts at several crypto‑security firms estimate that the compromised wallets belonged to high‑net‑worth individuals and institutional investors, with total losses exceeding $130 million. The stolen funds have been moved through a series of mixers before landing on exchanges known for lax KYC procedures.
Response from Coldcard and the Community
Coldcard’s manufacturer, Coinkite, issued an emergency firmware update that patches the vulnerability and advises users to immediately upgrade. The company also recommends users generate new seed phrases and transfer assets to fresh devices as a precaution.
- Update to the latest firmware released on August 3, 2026
- Generate a new seed phrase on a clean device
- Move funds to a newly initialized wallet
- Enable multi‑signature safeguards where possible
Implications for Hardware Wallet Security
The incident underscores that even air‑gapped devices are not immune to sophisticated attacks. Experts warn that reliance on offline storage alone is insufficient without regular security audits and prompt patch management.
“This breach is a stark reminder that hardware wallets must be treated as software as well as a physical device,” said a senior analyst at a leading blockchain security firm.
Users are urged to stay vigilant, monitor their balances, and report any suspicious activity to their wallet providers.