Loading market data...

Coldcard Firmware Flaw Drained $89M in Bitcoin, Thousands of Wallets Hit

Coldcard Firmware Flaw Drained $89M in Bitcoin, Thousands of Wallets Hit

A critical flaw in Coldcard's firmware allowed hackers to steal $89 million in Bitcoin this week, hitting thousands of wallets. The exploit is a stark reminder that hardware wallets aren't invincible, and it may push users back toward centralized exchanges for storage.

How the attack worked

The attackers exploited a vulnerability in the firmware that runs on Coldcard devices. Details are scarce, but the breach allowed them to siphon funds from wallets that were thought to be secure. The theft affected a wide range of users, from individual holders to small businesses. Coldcard has not yet released a full technical breakdown of the exploit.

The scale of the damage

With $89 million gone, this is one of the largest hardware wallet exploits on record. Thousands of wallets were compromised, though Coldcard has not confirmed the exact number. The incident underscores the critical need for robust firmware security across the industry. Hardware wallets are often considered the gold standard for self-custody, but this breach shows that no layer is immune.

Community reaction

On social media, Coldcard users expressed frustration and demanded answers. Some called for a full disclosure of the vulnerability. Others questioned whether hardware wallets are still the safest option for long-term storage. The incident has reignited the debate over self-custody versus exchange custody.

The timing isn't great for the self-custody movement. If users lose faith in hardware wallets, they might turn back to centralized exchanges for storage. Exchanges often offer insurance and active monitoring, but they also introduce counterparty risk. The exploit may shift trust back to centralized exchanges for Bitcoin storage, as the facts note. It's a bitter irony: the very tool designed to eliminate third-party risk may drive users back to it.

Coldcard has not released a patch yet. Users should consider moving their Bitcoin to a different wallet or exchange until the vulnerability is resolved. The crypto community is waiting for a detailed post-mortem and a timeline for a firmware fix.