Coldcard Wallet Maker Tightens Security After $130M Bitcoin Theft Linked to Old Flaw
Coinkite, maker of the popular Coldcard hardware wallet used to store Bitcoin offline, has changed how its devices generate the secret "seed" phrases that protect users' funds. The move follows reports that attackers exploited a years-old flaw in the wallet's firmware, contributing to a theft campaign estimated at roughly $130 million in stolen Bitcoin.
Hardware wallets are designed to be one of the most secure ways to store cryptocurrency, keeping private keys offline and away from internet-connected devices. However, this incident shows that even specialised security hardware can carry hidden weaknesses that go undetected for years until attackers find and exploit them at scale.
While this case involves cryptocurrency users specifically, it's a useful reminder for any business relying on hardware security devices, tokens, or specialised equipment: firmware and software updates matter, even for products marketed as highly secure. Businesses holding digital assets should stay alert to vendor security advisories and apply updates promptly.