Hackers steal over $130M by exploiting bug in offline hardware wallets
Hackers have stolen more than $130 million by exploiting a security vulnerability in Coldcard, a cryptocurrency hardware wallet built for offline use.…
By Dillip Chowdary • Aug 05, 2026 • Source: TechCrunch
Hackers have stolen more than $130 million by exploiting a security vulnerability in Coldcard, a cryptocurrency hardware wallet built for offline use. Blockchain-monitoring firms put the total losses above that figure after tracking drained victim wallets. The attack targets devices marketed as a high-assurance way to hold private keys away from always-online software.
Coldcard is an offline hardware wallet: private keys stay on the device rather than in hot wallets or browser extensions. The reported bug breaks that isolation in practice and lets attackers empty funds from affected wallets. Beyond naming Coldcard and the offline design, public reporting so far centers on impact size, not a full public technical teardown of the exploit path.
Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
For engineers and builders, the case is a direct hit on the hardware-wallet threat model. Offline storage is often treated as the last line of defense after exchange and software-wallet risk. A defect that enables large-scale drainage shows that physical form factor and air-gapped marketing do not replace rigorous review of firmware, signing flows, and supply-chain or physical-access assumptions.
The market context is the premium tier of self-custody. Users choose hardware wallets specifically to reduce remote theft risk relative to phones and desktop apps. Losses above $130 million on a single product line are large enough to pressure trust in that category and to force competitors and custodial services to answer how their offline or semi-offline designs differ under the same class of failure.
Practical takeaway: treat Coldcard holdings as under active risk until the vendor and independent researchers publish a clear root cause, fixed builds, and a migration or recovery path. Watch for official vendor advisories, firm-level loss updates from the same blockchain monitors, and whether other offline wallet makers issue related guidance. Do not invent or assume version numbers or patch IDs that are not yet confirmed.
Advertisement