
A Coldcard seed generation flaw let hackers steal over $100 million. The breach challenges cold storage's safety and questions open-source code vetting.
Alpha Score of 58 reflects moderate overall profile with strong momentum, strong value, moderate quality, poor sentiment.
A vulnerability in how Coinkite generated seed phrases for its Coldcard hardware wallets allowed attackers to steal more than $100 million from users, the company disclosed. The flaw came from a failsafe that introduced predictable information, such as serial numbers, into the random generation process. Hackers used that knowledge to brute force their way into thousands of wallets.
Cold storage has long been considered the gold standard for crypto security. Users store seed phrases offline on devices like USB sticks or hard drives. The Coldcard breach shows that even physical offline methods can fail when the underlying code has a hidden weakness.
Coinkite's firmware was open source, standard practice in crypto. White-hat hackers can review the code and report vulnerabilities for rewards. The ratio of users who can independently assess a wallet provider's code is shrinking as adoption grows, Bloomberg Opinion's Emily Nicolle wrote.
Beyond code flaws, physical threats are rising. Wrench attacks, where criminals coerce victims into handing over passwords, have surged. France accounted for 38% of documented wrench attacks since early 2025, according to a database compiled by security expert Jameson Lopp. The crypto elite now spends heavily on bodyguards.
Industry efforts to improve security have met resistance. Ledger, another cold storage maker, launched a product that split seed phrases into three fragments stored in different countries. Users reacted with anger, feeling the company had betrayed their trust. The product eventually launched with extra transparency.
For retail holders, the Coldcard episode reinforces a trade-off. Storing crypto on exchanges carries its own risks, as the collapses of FTX, Celsius and Mt. Gox showed. Bitcoin ETFs from mainstream asset managers offer price exposure without the custody burden, Nicolle noted. For most casual investors, that may be the safer path.
Coinkite said it has patched the seed generation flaw. The company did not disclose how many wallets remain compromised.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.