Coldcard Hardware Wallets Compromised: Over $130 Million Stolen via Seed Phrase Flaw
Blockchain security firms report that over $130 million has been stolen from Coldcard hardware wallet users. Multiple groups of hackers are reportedly exploiting a critical vulnerability in the devices, which are typically considered a highly secure, air-gapped method for storing Bitcoin.
Security researchers at Block discovered that the flaw lies in the predictable way Coldcard wallets generate seed phrases. This vulnerability allows attackers to compromise the secret keys that protect users' assets, effectively bypassing the security benefits of offline storage.
Personal take & trading angle
This incident is deeply concerning as it undermines the 'cold storage' security narrative that many long-term holders rely on. For investors, this serves as a stark reminder that even hardware solutions are subject to supply chain or manufacturing bugs, and it may trigger a short-term flight to more established or diverse security practices. Traders should view this as a potential catalyst for increased volatility in hardware-related security sectors, as users may look to rotate into multi-signature setups or different wallet providers to mitigate these risks.