Briev
Live
Technology

Coldcard's seed-phrase flaw lets thieves steal over $100 million in Bitcoin

Coldcard’s hardware wallets were compromised after the company used a predictable method to generate seed phrases, enabling hackers to steal at least $100 million worth of Bitcoin from users who thought their funds were safe.

Coldcard, a niche provider of offline Bitcoin wallets, suffered a major security breach after it used a non-random, predictable process to generate seed phrases. Hackers who obtained one seed phrase could employ trial-and-error techniques to infer additional phrases, allowing them to siphon at least $100 million in Bitcoin from customers who believed their holdings were protected. While the company’s market share is under 2 % and the broader crypto market showed little reaction, the incident is symbolic because it targeted knowledgeable users who stored their coins in cold storage.

Analysts argue the loss stems from the manufacturer’s negligence rather than any flaw in Bitcoin itself. The episode also fuels debate over the practicality of hardware wallets versus trusting reputable exchanges for modest crypto balances.

Why it matters

It shows that even highly secure-looking crypto wallets can be compromised by poor design, threatening user confidence in self-custody.

In this story

Coldcardseed phraseBitcoin hackhardware walletcrypto securityself-custodyoffline walletsecurity lapsecryptocurrency theft