Years-Old Coldcard Wallet Flaw Still Being Exploited to Steal Bitcoin
A security flaw in the firmware of Coldcard, a hardware wallet used to store Bitcoin, has reportedly enabled an ongoing theft campaign that has continued for years despite the vulnerable firmware being released back in 2021. The persistence of losses raises questions about how quickly affected users have applied security updates and whether outdated firmware remains widely in use.
Hardware wallets are marketed as one of the most secure ways to store cryptocurrency, but this case highlights that even dedicated security devices can carry exploitable flaws. When vulnerabilities in firmware go unpatched by end users, attackers can exploit them long after a fix becomes available, turning a one-time bug into a long-running source of theft.
For Australian small businesses holding or transacting in cryptocurrency, this incident is a reminder that any device — not just laptops and phones — needs to be kept updated. Firmware updates for hardware wallets, routers, and other embedded devices are often overlooked compared to software updates on computers.