Loading market data...

Coldcard Exploit Drains $89M, Bitcoin Flows to Exchanges in Reversal of FTX-Era Behavior

Coldcard Exploit Drains $89M, Bitcoin Flows to Exchanges in Reversal of FTX-Era Behavior

A security exploit targeting Coldcard hardware wallets has resulted in the theft of roughly $89 million in bitcoin, according to on-chain data. In a sharp departure from the self-custody rush that followed the FTX collapse in late 2022, affected users are now moving their remaining funds to exchanges — a sign that trust in hardware wallets has taken a hit.

The $89 million hole

The exploit, which came to light this week, appears to have compromised a specific batch of Coldcard devices. The exact attack vector hasn't been publicly confirmed by the manufacturer, but blockchain sleuths tracked the stolen coins moving through multiple mixers and exchanges. Coldcard, a popular brand among bitcoin maximalists, has not yet issued a full post-mortem. The $89 million figure represents the total value of bitcoin siphoned from users' wallets.

Bitcoin moves to exchanges — a reversal

Data from Glassnode shows a net inflow of bitcoin to centralized exchanges over the past 48 hours, driven largely by Coldcard users. This is the opposite of what happened after FTX's implosion, when investors pulled coins off exchanges en masse to hold them in self-custody. The current flow suggests that some users now see exchange custody as safer than hardware wallets — at least for the moment.

The timing isn't great for the hardware wallet industry, which has long marketed itself as the gold standard for security. Coldcard's parent company, Coinkite, has faced criticism for its slow response. The company's support account on X posted a brief acknowledgment but has not detailed a fix or compensation plan.

What users are doing now

On Bitcoin-focused forums and Telegram groups, Coldcard owners are sharing advice on how to migrate to other hardware wallets or to software wallets with multi-sig setups. Some are simply selling their bitcoin on exchanges and moving to cash. The inflow to exchanges suggests a mix of panic selling and a temporary shift to custodial storage while users reassess their security setup.

What comes next

Coinkite is expected to release a firmware update and a detailed incident report within the next week. The company has not said whether it will offer reimbursements. Meanwhile, regulators in several jurisdictions are likely to take an interest — the exploit is large enough to draw attention from agencies that have been watching crypto security lapses. For now, the $89 million hole is a reminder that even the most trusted hardware can have a blind spot.