Industry News

Years-Old Coldcard Wallet Flaw Still Being Exploited to Steal Bitcoin

AMBCrypto · 18 Aug 2026
Key Takeaway If your business uses hardware wallets or other specialised devices, check for and apply firmware updates regularly rather than assuming the device is secure by default.

A security flaw in the firmware of Coldcard, a hardware wallet used to store Bitcoin, has reportedly enabled an ongoing theft campaign that has continued for years despite the vulnerable firmware being released back in 2021. The persistence of losses raises questions about how quickly affected users have applied security updates and whether outdated firmware remains widely in use.

Hardware wallets are marketed as one of the most secure ways to store cryptocurrency, but this case highlights that even dedicated security devices can carry exploitable flaws. When vulnerabilities in firmware go unpatched by end users, attackers can exploit them long after a fix becomes available, turning a one-time bug into a long-running source of theft.

For Australian small businesses holding or transacting in cryptocurrency, this incident is a reminder that any device — not just laptops and phones — needs to be kept updated. Firmware updates for hardware wallets, routers, and other embedded devices are often overlooked compared to software updates on computers.

Summarised by CISO AI from AMBCrypto. We link back to every original so you can read it yourself.