Hardware wallet exploit drains more than $130 million from Coldcard users
A security vulnerability in the Coldcard hardware wallet is being actively exploited, with blockchain monitoring firms attributing more than $130 million in losses to the attack as hackers drain cryptocurrency directly…
A security vulnerability in the Coldcard hardware wallet is being actively exploited, with blockchain monitoring firms attributing more than $130 million in losses to the attack as hackers drain cryptocurrency directly from victims' devices. Coldcard is purpose-built for offline self-custody, keeping private keys isolated from internet-connected systems. That design provided no protection once the bug was present in the device itself.
The breach in plain terms
Hardware wallets earn their position in a self-custody setup by keeping private keys off the internet. The device signs transactions locally. Nothing sensitive crosses a network connection. Users who distrust exchanges or centralized custodians rely on exactly this architecture as a step above software wallets and a full exit from counterparty risk.
The exploit breaks that premise at its base. The vulnerability sits inside the device itself, not in a connected service or an upstream phishing scheme. Coldcard's maker is private, so no publicly traded ticker is directly in focus. Blockchain monitoring firms are the sourced authority on the $130 million figure. The source framing, "bug in offline hardware wallets," identifies the attack surface as the defining feature of this product category rather than a lapse in user behavior.
That distinction matters. A device-layer flaw is harder to dismiss as user error.
What to watch
Hardware wallet firmware updates are not automatic. Devices designed to operate air-gapped do not receive patches the way internet-connected hardware does. The update process requires deliberate user action, which means the window between a patch being released and a patch being widely applied can stretch considerably across a user base that, by design, stays offline.
The next concrete milestones are a confirmed fix from Coldcard's maker and verification from the blockchain monitoring firms currently tracking outflows that the exploit vector has been closed.
Filed via techcrunch.com