← News·Markets · Digital AssetsMarkets

Hardware wallet exploit drains more than $130 million from Coldcard users

A security vulnerability in the Coldcard hardware wallet is being actively exploited, with blockchain monitoring firms attributing more than $130 million in losses to the attack as hackers drain cryptocurrency directly…

NM
NewsMV Markets Desk
3 min read
4 August 2026Markets desk
Share this dispatch

A security vulnerability in the Coldcard hardware wallet is being actively exploited, with blockchain monitoring firms attributing more than $130 million in losses to the attack as hackers drain cryptocurrency directly from victims' devices. Coldcard is purpose-built for offline self-custody, keeping private keys isolated from internet-connected systems. That design provided no protection once the bug was present in the device itself.

The breach in plain terms

Hardware wallets earn their position in a self-custody setup by keeping private keys off the internet. The device signs transactions locally. Nothing sensitive crosses a network connection. Users who distrust exchanges or centralized custodians rely on exactly this architecture as a step above software wallets and a full exit from counterparty risk.

The exploit breaks that premise at its base. The vulnerability sits inside the device itself, not in a connected service or an upstream phishing scheme. Coldcard's maker is private, so no publicly traded ticker is directly in focus. Blockchain monitoring firms are the sourced authority on the $130 million figure. The source framing, "bug in offline hardware wallets," identifies the attack surface as the defining feature of this product category rather than a lapse in user behavior.

That distinction matters. A device-layer flaw is harder to dismiss as user error.

What to watch

Hardware wallet firmware updates are not automatic. Devices designed to operate air-gapped do not receive patches the way internet-connected hardware does. The update process requires deliberate user action, which means the window between a patch being released and a patch being widely applied can stretch considerably across a user base that, by design, stays offline.

The next concrete milestones are a confirmed fix from Coldcard's maker and verification from the blockchain monitoring firms currently tracking outflows that the exploit vector has been closed.

Categorycrypto

Filed via techcrunch.com

Keep reading

More from the markets desk