A significant security incident affecting Coldcard hardware wallets has resulted in approximately $70 million in verified losses, according to research published by Galaxy Digital. The attack exploited a specific vulnerability in the device's firmware, allowing threat actors to drain cryptocurrency from nearly 1,200 compromised addresses. This incident underscores the persistent challenge that hardware wallet manufacturers face in balancing accessibility with airtight security protocols—a tension that remains unresolved even among industry leaders.
The technical nature of the vulnerability appears to have bypassed Coldcard's multi-signature capabilities and PIN protection mechanisms, suggesting either a sophisticated supply-chain compromise or a critical flaw in the device's key derivation process. Coldcard, manufactured by Coinkite, has long positioned itself as one of the most security-conscious hardware wallet providers, offering advanced features like air-gapped transaction signing and open-source firmware. The fact that attackers could circumvent these safeguards in such a systematic manner raises difficult questions about the assumptions underlying hardware wallet security models. The scale of the exploitation—1,200 addresses affected with consistent loss patterns—indicates this was not opportunistic theft but rather a coordinated campaign targeting a specific vulnerability that remained unpatched for some period.
This incident comes at a time when hardware wallets continue to serve as a critical infrastructure layer for self-custody, particularly among institutional investors and security-conscious individuals. The $70 million figure, while substantial, remains relatively small compared to historical exchange hacks, but its significance lies in what it reveals about the hardware wallet threat landscape. Unlike centralized platforms where security breaches are eventually detected and disclosed, hardware wallet vulnerabilities can silently drain users before anyone realizes a problem exists. The 1,200 affected users likely didn't discover their losses simultaneously, meaning the true scope of the incident may have taken weeks or months to understand fully.
Coldcard has since released firmware patches addressing the vulnerability, and users are being urged to update their devices immediately and verify their holdings. The company's response time and transparency will be closely watched by the community. As self-custody becomes increasingly important to the broader crypto ecosystem, particularly amid concerns about exchange solvency and regulatory uncertainty, ensuring that hardware wallet manufacturers maintain rigorous security standards remains paramount—making incidents like this a crucial test of whether current security architectures can truly match the demands of securing digital assets at scale.