CoinDesk reports that a bug tied to Coldcard’s code went unnoticed for years and has been linked to more than $100 million in stolen bitcoin. The report says the failure was not that attackers physically accessed hardware wallets, but that a weakness in how the wallets’ seed phrases were generated left users exposed. The most concrete individual case in the report is Jonathan Goodman, a Toronto entrepreneur who said his wallets were emptied on July 29. According to CoinDesk, Goodman said he had kept his Coldcard hardware wallet offline in a safe deposit box and stored his seed phrase separately, yet lost 18.25 bitcoin, worth just over $1.17 million at the time of the attack. CoinDesk cites Galaxy Research as saying it had “high confidence” that 1,596 bitcoin, worth more than $100 million, had been stolen from about 7,300 addresses in a series of attacks. Galaxy Research head Alex Thorn estimated on Aug. 4 that at least 15 different attackers were exploiting the flaw, according to the report. CoinDesk also reports that those attackers did not need physical access to the devices. That distinction matters because hardware wallets are sold around a simple security premise: the private keys should remain isolated from internet-connected machines. Coldcard is a cold wallet, meaning it is designed to keep keys on a separate device rather than on a phone, browser, or computer that is routinely online. In CoinDesk’s account, the breach cuts underneath that model by targeting the creation of the secret itself. A seed phrase is the recovery secret that protects access to a user’s coins. If that phrase is generated with inadequate randomness or otherwise predictable behavior, the device can be offline and still fail at the most important step: creating a secret that only the user can know. CoinDesk’s report frames the Coldcard incident as a reminder that air-gapping reduces one class of risk but cannot compensate for flawed key generation. The report also gives company context. Coinkite, the Toronto-based maker of Coldcard, told customers in March 2016 that it was sunsetting its hosted hot wallet, according to CoinDesk, after dealing with junk traffic, legal costs, and regulatory complications. Coldcard became part of the company’s move toward hardware custody, where users hold their own keys rather than rely on a hosted service. Who benefits: Attackers who could exploit the alleged seed-generation flaw benefited directly, according to CoinDesk’s report. Security researchers and custody teams also have a clear reason to re-examine wallet-generation processes. Who's exposed: The exposed group, as described by CoinDesk, is Coldcard users whose funds were tied to vulnerable seed generation. Coinkite also faces scrutiny because Coldcard is the product at the center of the report.