How to Protect Yourself From This Massive Ongoing Cryptocurrency Hack

Threat actors stole seed phrases from offline wallets.

How to Protect Yourself From This Massive Ongoing Cryptocurrency Hack

Emily Long

Emily Long Freelance Writer

Experience

Emily Long is a freelance writer based in Salt Lake City.

After graduating from Duke University, she spent several years reporting on the federal workforce for Government Executive, a publication of Atlantic Media Company, in Washington, D.C. She has nearly a decade of experience as a freelancer covering tech (including issues related to security, privacy, and streaming) as well as personal finance and travel.

In addition to Lifehacker, her work has been featured on Wirecutter, Tom’s Guide, and ZDNET. Emily has also worked as a travel guide around the U.S. and as a content editor. She has a masters in social work and is a licensed therapist in Utah.

Read Full Bio

August 4, 2026

Add as a preferred source on Google
Add as a preferred source on Google

Phone with a warning symbol over the top and floating paper money

Credit: Zooey Liao/Lifehacker/Getty Images

Key Takeaways

Bad actors have managed to steal more than $130 million in cryptocurrency from offline hardware wallets. Coldcard wallets had a vulnerability allowing hackers to brute-force users' seed phrases. Users should update their firmware and migrate to a new seed phrase.

Table of Contents


It seems no sooner does someone come up with a method to keep your digital data safe than hackers find a way to subvert it. Today's case in point: Bad actors have stolen more than $130 million in cryptocurrency from users of offline hardware wallets, devices specifically meant to be a safe option for securing bitcoin.

Hackers are attacking cold crypto wallets

As TechCrunch reports, multiple groups of hackers have gained access to Coldcard crypto wallets and are continuing to drain funds in an ongoing theft. The wallets, made by Coinkite, are considered "cold," meaning they are not connected to the internet or any other device, and users' keys or seed phrases exist entirely offline. By contrast, "hot" wallets are connected to the internet and include apps and browser extensions.

Typically, hot wallets are considered a greater security risk for hacks, theft, malware, and ransomware, but this latest attack exploited a flaw in Coldcard's seed phrase generation process, compromising users' cold wallets. The vulnerability made seeds predictable, so threat actors were able to brute-force victims' passwords—essentially, guess them via trial and error—and gain access to their wallets.

Hackers carried out more than 200 crypto attacks between January and July of this year, leading to losses of $972 million. That's an increase in the number of events, but a significantly lower amount stolen, compared to the first six months of 2025.

What do you think so far?

How to protect your cryptocurrency wallet

According to Coinkite's security advisory, the vulnerability has now been patched for all affected firmware, so users should first install available updates to their devices from the official download pages (linked in the advisory). Users should also migrate their wallets to a new seed phrase following the specific instructions in the advisory.

While using a cold wallet should provide greater protection, you may also consider a diversified storage strategy for your cryptocurrency and leave minimal assets in hot wallets at any given time. That way, if one is compromised, it doesn't leave everything vulnerable.