A hack targeting Coldcard hardware wallets has cost users more than $111 million, according to an analysis by Galaxy Digital. The breach is a stark reminder that even self-custody devices are not immune to compromise, and it puts firmware security squarely in the spotlight.
The $111 Million Toll
Galaxy Digital, a financial services firm that tracks digital asset markets, examined the hack and put the losses at over $111 million. That figure covers the stolen funds from Coldcard users, though the exact number of affected wallets or individuals hasn't been released.
Coldcard is a popular hardware wallet used by crypto holders who want to keep their private keys offline. The device is built around a secure element and is often marketed as a more advanced option for those who take self-custody seriously. So the scale of the loss is notable for a product that's supposed to be one of the most hardened on the market.
Why Firmware Security Matters
The hack highlights a critical need for rigorous firmware security in hardware wallets. Hardware wallets are only as strong as the code that runs on them. If an attacker can slip malicious instructions into the firmware, they can bypass the very protections that make these devices secure.
Galaxy Digital's analysis points to a vulnerability in the firmware as the entry point for the attack. That's a worrying sign for an industry where users are told to trust the device, not the exchange or the network. Firmware updates are supposed to fix bugs and close holes, but this incident shows that even the update process itself can be a weak link.
A Blow to Self-Custody
The hack challenges trust in self-custody solutions. For years, the pitch has been simple: hold your own keys, and you don't have to rely on a third party to keep your funds safe. Hardware wallets are the backbone of that promise. When one gets compromised, it shakes the confidence of everyone who's been told to move their money off exchanges.
It also raises a practical question for Coldcard users: what now? The company hasn't issued a public statement in the data we have, so it's unclear whether a patch is available or if users need to move their funds. What's clear is that this incident will make many people think twice before assuming their hardware wallet is impenetrable.
The question now is whether other hardware wallet makers will take a harder look at their own firmware in light of this attack. For users, the immediate concern is whether their assets are safe and what steps they can take to protect them. Until Coldcard or Galaxy Digital provides more detail, the full picture of how the hack happened and who was affected remains open.




