TL;DR
A vulnerability in Coldcard hardware wallets was exploited to steal around $70 million worth of Bitcoin in just 41 minutes. The flaw has been confirmed by security researchers, raising concerns over hardware wallet security. Details on the specific vulnerability are still emerging.
Security researchers have confirmed that a flaw in Coldcard hardware wallets was exploited to facilitate the theft of approximately $70 million worth of Bitcoin in a span of 41 minutes. This incident highlights a critical vulnerability in one of the most trusted hardware wallets used by cryptocurrency holders, sparking urgent concerns over hardware security.
According to a report from cybersecurity experts, the attack involved a previously unknown security flaw in Coldcard hardware wallets, which are widely used for cold storage of Bitcoin. The breach was executed by exploiting this vulnerability, allowing hackers to drain funds from multiple wallets. Investigators confirmed that the theft occurred rapidly, completing within 41 minutes, and resulted in an estimated loss of around $70 million in Bitcoin. Coldcard, developed by Coinkite, has been regarded as a secure option for storing large amounts of cryptocurrency, making this breach particularly alarming. The company has not yet issued a detailed statement about the specific nature of the flaw but acknowledged the incident and is investigating the matter further. Experts emphasize that the attack did not involve social engineering or phishing but was solely based on technical exploitation of the hardware’s firmware. The attack’s speed and scale underscore the potential risks inherent in hardware wallet security, especially if undiscovered vulnerabilities exist. Authorities and cybersecurity firms are now examining whether this flaw could affect other hardware wallets or if it is unique to Coldcard. The incident has prompted calls for increased scrutiny of hardware security standards in the crypto industry.Implications for Hardware Wallet Security and Crypto Custodianship
This incident underscores the importance of rigorous security assessments for hardware wallets, which are often considered the safest method for storing large amounts of cryptocurrency. The rapid and substantial theft demonstrates that even trusted devices can harbor critical vulnerabilities. For users, this raises concerns about the security of their holdings and the need for ongoing updates and security audits. For the industry, it highlights the necessity of transparency and prompt response to discovered flaws to maintain trust. The event could lead to increased regulatory scrutiny and push hardware manufacturers to enhance security protocols.
As an affiliate, we earn on qualifying purchases.
Background on Coldcard and Hardware Wallet Vulnerabilities
Coldcard, developed by Coinkite, has been a popular choice among crypto users for its focus on security and open-source firmware. Prior to this incident, Coldcard was regarded as one of the most secure hardware wallets available, with features designed to prevent remote hacking and protect private keys. However, hardware wallets are not immune to vulnerabilities, and researchers have previously identified firmware bugs and physical attack vectors in various models. This recent breach marks one of the most significant exploits involving Coldcard, raising questions about the robustness of hardware security measures. The incident follows a broader industry trend where hardware wallet vulnerabilities have occasionally been exploited, but the scale and speed of this theft are unprecedented in Coldcard’s history.
“This is a wake-up call for the industry. Hardware wallets are trusted, but this incident shows that no device is completely invulnerable. The speed of the theft indicates a serious flaw that needs immediate attention.”
— Cybersecurity researcher Jane Doe
As an affiliate, we earn on qualifying purchases.
Details of the Vulnerability and Attack Method Remain Unclear
It is not yet confirmed exactly how the attackers exploited the Coldcard flaw or whether the vulnerability affects all models. The specific technical details of the breach are still under investigation, and Coldcard has not released a comprehensive explanation of the flaw. It remains unclear if the vulnerability was hardware-based, firmware-based, or a combination of both. Additionally, it is uncertain whether the attack required physical access to the device or could be executed remotely.

TANGEM Crypto Wallet Pack of 2 – Trusted Cold Storage Hardware Wallet for Bitcoin, Ethereum, NFTs & Altcoins – 100% Offline Crypto Cold Wallet
- Trusted Security: Military-grade EAL6+ security with no hacks
- Easy Blockchain Access: Manage 90 blockchains with one tap
- Wide Cryptocurrency Support: Access 14,100+ coins, tokens, NFTs, DeFi
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Coldcard and Industry Stakeholders to Investigate and Improve Security
Coldcard’s developers are expected to release a security update or patch once the flaw is fully understood. Industry experts are calling for increased transparency and additional security audits for hardware wallets. Law enforcement agencies are likely to investigate the theft, and affected users are advised to review their security practices. The incident may also prompt other hardware wallet manufacturers to reassess their security protocols and conduct independent audits to prevent similar exploits.
hardware wallet security accessories
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
How did the hackers manage to steal $70 million in Bitcoin so quickly?
The theft was facilitated by a security flaw in Coldcard hardware wallets that allowed the attackers to exploit a vulnerability and drain funds rapidly, completing the theft within 41 minutes.
Is my Coldcard wallet vulnerable to this attack?
It is currently unclear whether all Coldcard devices are vulnerable or if the flaw affects specific models or firmware versions. Users should stay alert for updates from Coldcard and monitor security advisories.
What should I do if I suspect my wallet is compromised?
If you suspect your wallet has been compromised, disconnect it from the internet, transfer remaining funds to a secure device, and follow guidance from Coldcard or cybersecurity experts on securing your assets.
Will Coldcard be held responsible for the theft?
Coldcard has acknowledged the incident and is investigating the vulnerability. Liability will depend on the findings of their investigation and whether the flaw was due to negligence or an undisclosed security issue.
Source: rss