Cryptocurrency Hacks Continue to Plague Users of Offline Hardware Wallets
It’s a disturbing trend that seems to be repeating itself in the world of cryptocurrency: hackers finding new ways to subvert even the most secure methods of protecting digital data. The latest case in point involves the theft of over $130 million in cryptocurrency from users of offline hardware wallets, devices specifically designed to be a safe option for securing bitcoin.
According to reports from TechCrunch, multiple groups of hackers have gained access to Coldcard crypto wallets, which are considered ‘cold’ due to their lack of internet connectivity. These wallets, made by Coinkite, are designed to store users’ keys or seed phrases entirely offline, making them a more secure option compared to ‘hot’ wallets, which are connected to the internet and include apps and browser extensions.
However, the hackers have exploited a flaw in Coldcard’s seed phrase generation process, compromising users’ cold wallets. The vulnerability made seeds predictable, allowing threat actors to brute-force victims’ passwords through trial and error and gain access to their wallets.
This latest attack is part of a larger trend of cryptocurrency hacks, with over 200 attacks carried out between January and July of this year resulting in losses of $972 million. While this number is lower compared to the first six months of 2025, it highlights the ongoing threat of cryptocurrency hacks and the need for users to take proactive steps to protect themselves.
How to Protect Your Cryptocurrency Wallet
Coinkite has since patched the vulnerability in all affected firmware, and users are advised to install available updates to their devices from the official download pages. Additionally, users should migrate their wallets to a new seed phrase following the specific instructions provided in the security advisory.
While using a cold wallet provides greater protection, users may also consider a diversified storage strategy for their cryptocurrency, leaving minimal assets in hot wallets at any given time. This way, if one is compromised, it doesn’t leave everything vulnerable.
It’s essential for users to stay vigilant and take proactive steps to protect their cryptocurrency wallets. By following the steps outlined above and staying informed about the latest security threats, users can minimize their risk of falling victim to a cryptocurrency hack.
Key Takeaways:
- Over $130 million in cryptocurrency has been stolen from users of offline hardware wallets.
- The hackers exploited a flaw in Coldcard’s seed phrase generation process, compromising users’ cold wallets.
- Coinkite has patched the vulnerability in all affected firmware, and users should install available updates to their devices.
- Users should migrate their wallets to a new seed phrase following the specific instructions provided in the security advisory.
- Users should consider a diversified storage strategy for their cryptocurrency, leaving minimal assets in hot wallets at any given time.