Old Coldcard Wallet Flaw Blamed for $115 Million in Stolen Bitcoin
New research from Galaxy Research has linked a firmware vulnerability in Coldcard, a popular hardware wallet used to store cryptocurrency, to the theft of more than $115 million in Bitcoin. The flaw, which dates back to 2021, allowed attackers to compromise devices and drain funds from hundreds of victims over time.
Hardware wallets are often marketed as one of the safest ways to store digital assets because they keep private keys offline. This case shows that even purpose-built security devices can contain flaws that, if left unpatched, create serious risk—especially when losses can go undetected for years before being traced back to a single root cause.
While this incident centres on cryptocurrency users, the lesson applies broadly: any hardware or software device holding sensitive data or funds needs regular firmware updates and monitoring, and vendors need to be transparent when vulnerabilities are discovered.