Hackers steal over $130 million by exploiting bug in offline hardware wallets

Hackers have stolen over $130 million from users of Coldcard hardware wallets by exploiting a vulnerability in how the devices generate seed phrases. This breach challenges the perceived security of offline 'cold' storage solutions for cryptocurrency.
Why it matters
The theft underscores significant security risks in the cryptocurrency ecosystem, even for users who follow best practices by keeping assets offline.
Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists.
At least a dozen different hackers are said to be targeting Bitcoin owners who use the hardware crypto wallet Coldcard, made by Coinkite. At this point, it’s unclear who is behind the digital robberies, and it appears like there’s more than one group of hackers, according to Galaxy Research .
As of Tuesday, the research firm said the hackers have stolen around $130 million. Tom Robinson, the co-founder and chief scientist of crypto monitoring firm Elliptic, told TechCrunch that the estimate is roughly correct.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in