Hackers have stolen over $130 million from Bitcoin owners using Coldcard hardware wallets, according to blockchain security firms. At least a dozen hackers are targeting these offline crypto storage devices, exploiting a flaw in the seed phrase generation process.
Despite their supposedly secure design – with secret keys stored offline and away from internet threats – Coldcard users found themselves victims of brute-force attacks. Jonathan Goodman, a victim who claims to have lost $1.6 million, was left scratching his head: “I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes,” he wrote.
Coinkite, the manufacturer of Coldcard wallets, has since issued an advisory urging users to update their devices and generate a new seed phrase. This incident highlights that no storage method is completely impervious to cyber threats, even those designed to be offline and secure.
To date in 2023, more than 200 hacks targeting cryptocurrency companies have resulted in over $950 million in losses, according to blockchain monitoring firm TRM Labs. This ongoing theft underscores the need for continuous vigilance and improvement of security measures in the crypto world.







