Coldcard hardware wallet firmware bug exploited for $115M+ in ongoing attacks after years of going undetected.
Security & Exploits ·
A years-old bug in Coldcard's firmware has been linked to over $115M in stolen funds, with the exploitation still underway across thousands of user addresses. Galaxy Research identified approximately 1,596 bitcoin stolen from roughly 7,300 addresses, with at least 15 different attackers exploiting the flaw. The vulnerability affected how Coldcard generated seed phrases—the secret passwords protecting users' cryptocurrency—rather than compromising the hardware device itself.
The breach undermines a core security proposition of hardware wallets: that private keys never leave the device and remain inaccessible without physical access. Users following standard security practices, including keeping devices offline and storing seed phrases separately, nonetheless lost funds. The attackers required no physical access to exploit the flaw, breaking the air-gapped security model that distinguishes hardware wallets from internet-connected alternatives.
The incident raises questions about how the bug remained undetected for years and what steps Coinkite, the wallet's maker, has taken to address the vulnerability or notify affected users. The scope and ongoing nature of the attacks suggest continued exposure for remaining Coldcard users.