• Tech Tech

Hackers drained $130 million in Bitcoin from 7,300 'cold' wallets once billed as secure

"It exposes the fallacy of your crypto being offline."

A Bitcoin wallet.

Photo Credit: iStock

A tool meant to keep Bitcoin far from online thieves has become the latest reminder that "offline" does not always mean untouchable.

An ongoing exploit in Coldcard hardware wallets has cost users tens of millions of dollars, hitting devices that many in cryptocurrency had treated as one of the safest places to keep Bitcoin, Bloomberg reported.

What happened?

In late July, Canada-based Coinkite Inc. told users that some Coldcard devices had produced vulnerable seed phrases — the strings of words used to access a wallet.

By August 3, Galaxy Research said around 7,300 addresses had been compromised, with an estimated $130 million stolen. 

Engineers at Block Inc. traced the issue to the wallets' random-number generation. In affected firmware, seed phrases were not always fully unpredictable and could instead be derived from deterministic inputs such as device serial numbers, making them far easier for attackers to reconstruct.

For people who chose cold storage specifically to avoid internet exposure, the attack was shocking.

Jonathan Goodman, one of the victims, wrote on X, "My Bitcoin was in cold storage. My keys were on a ColdCard device kept in a safety deposit box that had never been connected to the internet."

Why does it matter?

Cold wallets are popular because keeping crypto off the internet is supposed to reduce exposure to online attacks. But the Coldcard breach has shown that separation from the web means little if the software that creates the wallet's keys is flawed.

As Aneirin Flynn, chief executive officer of cybersecurity technology firm Failsafe, told Bloomberg, "It exposes the fallacy of your crypto being offline. The device is just responsible for generating your passwords, and if the underlying math is broken then your passwords can be reverse-engineered."

Crypto transactions are generally irreversible, which makes stolen funds difficult to recover.

TRM Labs said crypto theft totaled $972 million in the first half of 2026, down from $2.3 billion in the same stretch last year. Even so, the number of hacks rose to 207, the highest ever recorded over a six-month period.

Supporters of cryptocurrency often point to financial independence and even the potential for some operations to support cleaner energy development, while critics cite major security risks and the heavy electricity demands tied to parts of the industry, especially Bitcoin mining.

What's being done?

Coinkite said fixed firmware is now available for every affected model and release track, while also warning that "funds controlled by seeds generated on affected firmware are at risk."

Users with affected devices cannot assume offline storage still protects them. It can still reduce some risks, but it cannot compensate for weak software design.

Recalling the moment he checked his wallet, Goodman said, "The moment it loaded I knew I was screwed because I saw red lines for withdrawals."

Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.

Cool Divider