Industry News

Old Coldcard Wallet Flaw Blamed for $115 Million in Stolen Bitcoin

Blockonomi · 18 Aug 2026
Key Takeaway If your business uses hardware security devices (wallets, tokens, or authentication keys), keep firmware updated and monitor vendor security advisories closely.

New research from Galaxy Research has linked a firmware vulnerability in Coldcard, a popular hardware wallet used to store cryptocurrency, to the theft of more than $115 million in Bitcoin. The flaw, which dates back to 2021, allowed attackers to compromise devices and drain funds from hundreds of victims over time.

Hardware wallets are often marketed as one of the safest ways to store digital assets because they keep private keys offline. This case shows that even purpose-built security devices can contain flaws that, if left unpatched, create serious risk—especially when losses can go undetected for years before being traced back to a single root cause.

While this incident centres on cryptocurrency users, the lesson applies broadly: any hardware or software device holding sensitive data or funds needs regular firmware updates and monitoring, and vendors need to be transparent when vulnerabilities are discovered.

cryptocurrency vulnerability hardware security

Summarised by CISO AI from Blockonomi. We link back to every original so you can read it yourself.