SAN FRANCISCO — Jonathan Goodman did everything right. He kept his Coldcard wallet offline. He never shared his seed phrase with anyone. He stored his Bitcoin on a hardware device specifically designed to make digital theft impossible. On Monday, someone emptied his account anyway, taking $1.6 million.
Goodman is one of dozens of victims in a breach that researchers at Block and analytics firm Elliptic say has cost Coldcard users more than $130 million. At least twelve distinct hacking groups have been involved, according to Galaxy Research. The flaw they exploited was not in how victims behaved. It was in how Coldcard manufactured its devices.
Coldcard, made by the Toronto-based company Coinkite, occupies a particular place in the Bitcoin community. It is not mass-market. It targets buyers who take security seriously enough to pay a premium for a dedicated hardware wallet, connect it to a computer as rarely as possible, and keep it powered off the rest of the time. Users who purchased Coldcard were, almost by definition, people who had thought harder than average about protecting their funds. That calculus has now reversed.
The vulnerability that made this possible traces back to 2021, when Coinkite introduced code with a flaw in its random number generator. Seed phrases, the 12 to 24 words that function as a master password for a cryptocurrency wallet, are supposed to be generated using genuine randomness. If that randomness is predictable, the seed phrases become reproducible. According to Block’s security researchers, Coldcard’s random number generator produced seed phrases that were not truly random: they were predictable enough for an attacker to reconstruct them without ever touching the physical device.
Hackers who knew about the vulnerability could generate the same seed phrases that a compromised Coldcard device would produce, covering every wallet initialized with the vulnerable firmware. The attack required no internet access to the victim’s device, no phishing, no social engineering. It was a computation problem: given enough processing power and knowledge of the algorithm, every key the device had ever generated was potentially recoverable. The fact that the wallet sat unplugged in a drawer was irrelevant.
The cold storage model, resting on the premise that a device never connected to the internet cannot be hacked remotely, is the foundational security claim of the hardware wallet industry. This breach does not invalidate offline storage entirely, but it demonstrates that algorithmic weaknesses inside the device can be as dangerous as network exposure. Security failures do not always arrive through the internet. Earlier this year, researchers conducting cybersecurity tests on AI systems discovered that offline isolation is also insufficient when the underlying logic is flawed, a pattern now repeating itself in hardware.

Coinkite published a security advisory on Thursday and updated it on Saturday, directing users to update their device firmware and migrate any funds in affected wallets to a new seed phrase generated on updated hardware. The company did not respond to requests for comment. No compensation mechanism has been announced.
The Coldcard breach is the largest single hardware wallet theft in 2026, a year that has already been unusually damaging for cryptocurrency holders. More than 200 hacks have targeted cryptocurrency platforms and users this year, with total losses exceeding $950 million. The Coldcard incident adds $130 million to that figure and introduces a category of theft, hardware vulnerability exploitation, that existing loss tallies have not fully tracked.
Elliptic and Galaxy Research declined to identify specific victims beyond Goodman, who agreed to be named publicly. The dozen hacking groups appear to have operated independently, each targeting a different subset of wallets, suggesting the vulnerability information circulated in underground markets before Coinkite became aware of it. The pattern echoes how state-backed attackers have operated in other infrastructure contexts, including the Iran hackers who hit Minnesota water systems last week, exploiting known weaknesses before operators had patched them.
For current Coldcard owners, Coinkite’s guidance is unambiguous: update the device firmware and create a new seed phrase on updated hardware, then transfer all funds to the new wallet. Wallets initialized after the firmware fix are not affected. Wallets initialized under vulnerable firmware are potentially compromised whether or not an attack has yet occurred. Goodman said he had no warning before his balance reached zero.
According to TechCrunch, which first reported the breach, neither Block nor Elliptic identified the total number of compromised wallets or provided a timeline for when the exploitations began. Coinkite’s advisory does not specify whether the company was aware of the vulnerability before Block’s researchers disclosed it.
What the breach does not answer is whether Coldcard is alone. Other Bitcoin hardware wallet manufacturers, including Ledger, Trezor, and Foundation Devices, have made no statements about whether their own random number generator implementations have been audited for similar weaknesses in the wake of the Coldcard disclosure. The assumption that hardware wallets are categorically safer than software alternatives has not been withdrawn by anyone in the industry. It has simply been complicated.

