Golden Bitcoin coins sitting on top of a stack of hundred-dollar bills.

Cold Vault Crack: Hackers Drain $130M From Offline Crypto Hardware Wallets

Hackers are currently pulling off a massive wave of cryptocurrency thefts targeting supposedly unhackable offline hardware wallets. Blockchain security companies monitoring digital assets confirmed the ongoing campaign, warning that multiple attacker groups are draining funds directly from high-value targets. Research firm Galaxy Research reports that at least a dozen distinct hacker groups are hunting down Bitcoin holders who store their digital funds on Coldcard hardware wallets made by Coinkite.

Data from crypto-monitoring firm Elliptic puts the current total stolen at around $130 million, a figure confirmed by industry researchers. This latest campaign adds to a brutal year for digital asset owners. According to blockchain analytics company TRM Labs, bad actors have launched over 200 separate attacks against cryptocurrency services and individual holders this year, with total losses soaring past $950 million.

What makes these attacks on Coldcard users so shocking is the fundamental promise of hardware wallet security. Investors buy devices like Coldcard specifically to keep private keys offline and away from internet threats. Under standard operations, a Bitcoin holder stores secret recovery seed phrases on a dedicated hardware device disconnected from any network. While the actual Bitcoin lives on the public ledger, access to those funds requires the offline key. Storing keys on dedicated physical hardware is widely considered far safer than holding assets on hot wallets, web browser extensions, or commercial exchanges like Binance and Coinbase.

However, security researchers at Block uncovered a critical vulnerability in how Coldcard devices generated those secret seed phrases. The wallet software contained a hidden flaw that made created key phrases predictable under specific conditions. Once attackers identified this pattern, they did not need to break into physical devices or trick users with phishing sites. Instead, they simply ran automated brute-force scripts to calculate secret recovery phrases and generate valid private keys at scale.

Knowing how to recreate the keys allowed hackers to access user funds without physically touching the devices or breaching secure storage locations. One victim, Jonathan Goodman, revealed on X that attackers stole $1.6 million worth of Bitcoin from his Coldcard setup despite strict safety precautions. He noted that he never shared his recovery phrase with anyone, never plugged his hardware into internet-connected computers, and stored backup sheets inside physical deposit boxes across multiple bank vaults. None of those safety measures mattered because a single line of vulnerable code introduced back in 2021 made his initial seed generation flawed from day one.

Coinkite issued a public security advisory urging all Coldcard owners to update their device firmware immediately. The manufacturer urged users to generate entirely new seed phrases on updated devices and transfer all remaining funds to fresh blockchain addresses right away. The incident proves that even air-gapped physical hardware can fail if the underlying cryptographic software contains flaws.