Hackers stole $130 million from ‘secure’ offline crypto wallets, and the victims did nothing wrong

The most unsettling detail in this story isn’t the $130 million. It’s a quote from one victim: ‘I did everything right.’ Jonathan Goodman says he never shared his seed phrase, never connected his devices to the internet, and kept everything locked in safes and safety deposit boxes. He still lost $1.6 million. That’s not a user error story. That’s a product failure story.

According to TechCrunch, security researchers at Block identified a flaw in how Coldcard hardware wallets, made by Coinkite, generated users’ seed phrases. The seed phrase is the master password to your cryptocurrency. It’s the thing you’re told to write down, lock away, and never show anyone. The problem is that Coldcard’s seed phrase generation process was predictable. Once attackers understood the flaw, they could brute-force their way to the correct phrases without ever touching a victim’s physical device.

Goodman put it plainly in a post on X: ‘None of it mattered. All because the hardware that created the seed phrase originally had one line in their code from 2021 that had a vulnerability.’ A single line of buggy code from four years ago. That’s the attack surface that drained millions from people who thought they were doing everything correctly.

Galaxy Research says at least a dozen separate hacker groups are involved in the ongoing theft. Crypto-monitoring firm Elliptic co-founder Tom Robinson confirmed the $130 million estimate is roughly accurate. The fact that multiple groups appear to be running parallel attacks suggests the vulnerability became known in criminal circles before it was publicly disclosed, which raises serious questions about how long this flaw was known, by whom, and whether Coinkite had any prior warning.

This matters beyond the immediate victims. Hardware wallets exist specifically because ‘hot’ wallets, meaning apps, browser extensions, and exchange accounts, are considered risky. Coldcard and devices like it are marketed to security-conscious Bitcoin holders as the safer alternative. If the seed phrase generation on an air-gapped device can be predicted and brute-forced, the fundamental promise of cold storage takes a serious hit.

The broader picture isn’t encouraging. Blockchain-monitoring firm TRM Labs counts more than 200 cryptocurrency hacks so far this year, totaling over $950 million in losses. This Coldcard incident is part of a pattern, not an anomaly. But what makes it stand out is that it targets people who specifically tried to protect themselves.

Coinkite published an advisory urging users to update their devices and migrate to a new seed phrase. The company did not respond to TechCrunch’s request for comment. That silence is worth noting. When a product’s core security function is compromised, users deserve a clear, public explanation of the timeline, the scope, and exactly which devices are affected. A brief advisory is not enough.