A vulnerability in how Coldcard hardware wallets generated seed phrases has been linked to the theft of more than $100 million in bitcoin from thousands of users, according to Galaxy Research.
Toronto entrepreneur Jonathan Goodman said his Coldcard wallet, which had never been connected to the internet and was stored in a safe deposit box, was emptied on July 29. He reported losing 18.25 bitcoin, worth just over $1.17 million at the time of the attack. "Perhaps the hardest part about this is that I did everything right," he wrote in an Aug. 1 X post.
Goodman's loss was part of a broader hack affecting thousands of Coldcard users. Galaxy Research said it had high confidence that 1,596 bitcoin — worth over $100 million — had been stolen from about 7,300 addresses in a series of attacks. Galaxy research head Alex Thorn estimated on Aug. 4 that at least 15 different attackers were exploiting the flaw. None of them needed physical access to a device.
Where the Flaw Originated
A hardware wallet's core security premise is that its secrets never leave the chip, making physical access the only way in. But in Coldcard's case, the vulnerability was not in the wallet device itself — it was in how the secret password, or seed phrase, protecting users' coins was generated.




