Home / Blog / Hackers steal over $130M by exploiting bug in offline…
Tech News

Hackers steal over $130M by exploiting bug in offline hardware wallets

Hackers have stolen more than $130 million by exploiting a security vulnerability in Coldcard, a cryptocurrency hardware wallet built for offline use.…

By Dillip Chowdary • Aug 05, 2026 • Source: TechCrunch

Hackers steal over $130M by exploiting bug in offline hardware wallets

Hackers have stolen more than $130 million by exploiting a security vulnerability in Coldcard, a cryptocurrency hardware wallet built for offline use. Blockchain-monitoring firms put the total losses above that figure after tracking drained victim wallets. The attack targets devices marketed as a high-assurance way to hold private keys away from always-online software.

Coldcard is an offline hardware wallet: private keys stay on the device rather than in hot wallets or browser extensions. The reported bug breaks that isolation in practice and lets attackers empty funds from affected wallets. Beyond naming Coldcard and the offline design, public reporting so far centers on impact size, not a full public technical teardown of the exploit path.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and builders, the case is a direct hit on the hardware-wallet threat model. Offline storage is often treated as the last line of defense after exchange and software-wallet risk. A defect that enables large-scale drainage shows that physical form factor and air-gapped marketing do not replace rigorous review of firmware, signing flows, and supply-chain or physical-access assumptions.

The market context is the premium tier of self-custody. Users choose hardware wallets specifically to reduce remote theft risk relative to phones and desktop apps. Losses above $130 million on a single product line are large enough to pressure trust in that category and to force competitors and custodial services to answer how their offline or semi-offline designs differ under the same class of failure.

Practical takeaway: treat Coldcard holdings as under active risk until the vendor and independent researchers publish a clear root cause, fixed builds, and a migration or recovery path. Watch for official vendor advisories, firm-level loss updates from the same blockchain monitors, and whether other offline wallet makers issue related guidance. Do not invent or assume version numbers or patch IDs that are not yet confirmed.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →