Coldcard Seed Flaw May Have Helped Hackers Rebuild Wallet Keys Through Weak Randomness and Brute-Force Attacks
A Coldcard hack reportedly stole Bitcoin from several wallets, causing heavy losses for some crypto holders. Blockchain investigators estimate that attackers may have taken 1,367.05 BTC from affected wallets.
Canadian entrepreneur Jonathan Goodman said he lost 18.25245043 BTC, worth about $1.6 million or Rs. 15 crore. The Bitcoin theft happened on July 29 between 9:36 pm and 9:43 pm.
Goodman said attackers emptied every wallet under his control within seven minutes. He kept his Coldcard device inside a safety deposit box and stored backup details separately.
He also said neither the device nor the seed phrase had ever connected to the internet. The incident therefore raised fresh questions about hardware wallet security.
Goodman shared his experience on X after learning about the reported Coldcard problem. He wrote, “All of my Bitcoin was stolen.”
The reported Coldcard hack involves a possible problem with seed phrase generation. Investigators say some affected wallets may have used weak randomness while creating seed phrases.
A seed phrase works like a key for a crypto wallet. Attackers who recover it can gain access to the Bitcoin stored within the wallet.
Goodman also claimed that attackers used AI-assisted brute force methods to find vulnerable seed phrases. He plans to report the incident to Canadian authorities, although he expects little chance of recovering the funds.
Other Coldcard users have reported similar losses on Reddit. Some users claimed they lost Bitcoin that took years to build through regular investments.
The incident raised concerns about crypto security and cold storage. Keeping Bitcoin offline can reduce risks, but secure seed generation remains equally important.
Disclaimer : Crypto News India does not recommend that any cryptocurrency should be bought, sold, or held by you. Do conduct your own due diligence and consult your financial advisor before making any investment decisions.
