$130M Stolen from Coldcard Wallets as Hackers Exploit Bug in Hardware
A group of hackers has exploited a bug in Coldcard hardware wallets to steal over $130 million from Bitcoin owners. The attack, which began earlier this year, is believed to involve at least a dozen different hackers.
The flaw was discovered in the way Coldcard generates users' seed phrases, which are essentially passwords that control access to cryptocurrency. Hackers were able to brute-force and generate the victims' seed phrases, effectively cutting keys at scale.
Coldcard owner Coinkite has issued an advisory urging users to update their devices and migrate to a new seed phrase. The company did not immediately respond to TechCrunch's request for comment.
Jonathan Goodman, who claimed to have had $1.6 million stolen from his Coldcard wallet, wrote on X that he followed all best practices to secure his assets, but the flaw in the hardware still allowed hackers to access his funds.