A security issue in offline hardware wallets has drawn attention after blockchain researchers reported a wave of cryptocurrency thefts tied to predictable seed phrases. The affected device, Coldcard by Coinkite, is designed to keep private keys away from the internet.
According to monitoring firms, attackers have targeted Bitcoin holders using the wallet and have already moved an estimated $130 million. Security specialists at Elliptic say the figure is broadly consistent with their own assessment, while TRM Labs reports that crypto-related hacks have surpassed 200 incidents this year, with losses above $950 million.
The core issue appears to be a flaw in how some wallets generated seed phrases, making them easier to predict than users expected. That weakness allowed attackers to recreate keys without physically accessing the device, turning a product built for protection into a point of exposure.
Coinkite has advised users to update their devices and move to a new seed phrase. The case is a reminder that even offline systems depend on the strength of their underlying code, and that secure design remains a moving target in digital finance.
As hardware wallets evolve, stronger randomness and faster security updates could help set a new standard for safeguarding digital assets in the future.