This is one outlet's own report from TechCrunch — the article as it was filed. Other outlets are covering the same event; open the full story to compare every source side by side.
Hackers steal over $130M by exploiting bug in offline hardware wallets Lorenzo Franceschi-Bicchierai 9:27 AM PDT · August 4, 2026 Hackers are in the midst of a massive theft of cryptocurrency from supposedly secure offline hardware wallets, according to blockchain security firms monitoring the heists.
At least a dozen different hackers are said to be targeting Bitcoin owners who use the hardware crypto wallet Coldcard, made by Coinkite. At this point, it’s unclear who is behind the digital robberies, and it appears like there’s more than one group of hackers, according to Galaxy Research .
As of Tuesday, the research firm said the hackers have stolen around $130 million. Tom Robinson, the co-founder and chief scientist of crypto-monitoring firm Elliptic, told TechCrunch that the estimate is roughly correct.
This is the latest effort to steal large amounts of people's cryptocurrency. So far this year, according to blockchain-monitoring firm TRM Labs , there have been more than 200 hacks targeting cryptocurrency companies, with a total loss of more than $950 million.
What makes the ongoing hacks against Coldcard wallet owners particularly interesting is that the point of using a product like Coldcard is that it’s supposed to be, at least in theory, one of the safer ways to store their cryptocurrency.
Bitcoin owners can store the secret key or seed phrase — essentially a password — to their cryptocurrency in a Coldcard wallet, a device that is not connected to the internet. With this system, Bitcoins are still on the blockchain, like all Bitcoins, but are protected by a password that lives exclusively offline. This is considered a “cold” wallet, as opposed to "hot" wallets that are online, such as those in apps, browser extensions, and accounts on commercial crypto exchanges like Binance or Coinbase.
As it turns out, hackers figured out that there was a flaw in how Coldcard wallets generated users' seed phrases, which were predictable, according to security researchers at Block . Once they figured out the flaw, hackers simply needed to brute-force and generate the victims’ seed phrases.
“Perhaps the hardest part about this is that I did everything right,” Jonathan Goodman, who claimed to have had $1.6 million stolen from his Coldcard wallet, wrote on X . “I never shared my seed phrase with anybody. My devices never touched the internet. Everything was kept in multiple safes and safety deposit boxes," he said.
"None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability,” wrote Goodman.
In an advisory published on Thursday and updated on Saturday, Coinkite alerted users of the flaw , urged them to update their devices, and then “migrate” to a new seed phrase.
Coinkite did not immediately respond to TechCrunch's request for comment.
When you purchase through links in our articles, we may earn a small commission . This doesn’t affect our editorial independence.
Lorenzo Franceschi-Bicchierai Senior Reporter, Cybersecurity
Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.
You can contact or verify outreach from Lorenzo by emailing [email protected] , via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.
October 13 – 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 toda y!
Sequoia's Shaun Maguire leads $1B round for nuclear startup Valar Atomics Julie Bort
YouTuber Hank Green says his AI usage is ‘not healthy’ Anthony Ha
WhatsApp is testing a new folder for messages from large businesses Ivan Mehta
Spotify adds a running mode to its app Ivan Mehta
Claude Opus 5 became downright ruthless when tasked with running a vending machine Julie Bort
DoorDash is building its own drone delivery business Kirsten Korosec
AIPROPX is an independent multi-source news index — we track, compare, and connect coverage from across the web into one place you won't find anywhere else.