Hackers steal over $130 million by exploiting bug in offline hardware wallets
Hackers are stealing cryptocurrency from supposedly secure offline hardware wallets, exploiting a bug in the Coldcard wallet's code. At least $130 million has been stolen so far.
Intelligence analysis by Llama

Hackers are targeting Bitcoin owners who use the Coldcard wallet, a supposedly secure offline storage device. They are exploiting a bug in the wallet's code to steal users' cryptocurrency.
Imagine you have a super-safe box where you keep your most valuable things. But what if someone found a way to guess the combination to that box? That's basically what happened with the Coldcard wallet. Hackers found a way to guess the combination to the box, and they stole a lot of money.
Analysis
A $60B Vote of Confidence in Cryptocurrency Security
The recent hacking of Coldcard wallets has left many in the cryptocurrency community reeling. At least $130 million has been stolen from users who thought their offline storage devices were secure. But what's behind this massive heist?
The answer lies in the code of the Coldcard wallet. Security researchers at Block discovered a flaw in the way the wallet generated users' seed phrases, which were predictable. This allowed hackers to brute-force and generate the victims' seedphrases, essentially cutting keys at scale.
The implications of this bug are far-reaching. It highlights the importance of security in cryptocurrency storage and the need for users to be vigilant. Even supposedly secure devices can be vulnerable to hacking, and users must take steps to protect themselves.
Why Cursor?
The hacking of Coldcard wallets raises questions about the security of other cryptocurrency storage devices. Are they vulnerable to similar attacks? What can be done to prevent such hacks in the future?
The answer lies in the development of more secure storage solutions. Companies like Coinkite, the maker of Coldcard, must prioritize security in their products. This includes regular updates and patches to fix vulnerabilities like the one exploited by hackers.
The Road Ahead
The hacking of Coldcard wallets is a wake-up call for the cryptocurrency community. It highlights the need for greater security and vigilance in the storage of cryptocurrency. Users must take steps to protect themselves, and companies must prioritize security in their products. Only then can we ensure the security and integrity of the cryptocurrency ecosystem.
Key points
- Hackers are stealing cryptocurrency from supposedly secure offline hardware wallets.
- The bug in the Coldcard wallet's code allowed hackers to brute-force and generate users' seedphrases.
- At least $130 million has been stolen from users so far.
- The hacking of Coldcard wallets highlights the importance of security in cryptocurrency storage.
- Companies like Coinkite must prioritize security in their products to prevent similar hacks in the future.
If the cryptocurrency community takes steps to improve security and vigilance, we can prevent similar hacks in the future. Companies like Coinkite can develop more secure storage solutions, and users can take steps to protect themselves.
The hacking of Coldcard wallets highlights the risks of cryptocurrency storage. If users are not vigilant and companies do not prioritize security, we can expect more hacks in the future.

