cryptocurrency

Over $130 million lost to a hardware wallet exploit you should know about

More than $130 million in cryptocurrency has been drained from hardware wallets through a bug in Coldcard devices.

3 min readTechCrunch
Over $130 million lost to a hardware wallet exploit you should know about

The scale of the damage is staggering: over $130 million drained from hardware wallets due to a vulnerability in Coldcard. For years, the pitch for these devices has been simple. Your crypto is safe because your private keys never touch the internet. That sense of absolute security has now been cracked, and the fallout is a reminder that no tool is a magic shield. This is not about Coldcard being uniquely sloppy. It is about the assumption that offline equals invulnerable, which is a dangerous oversimplification. We have seen similar patterns elsewhere. The recent North Korean hackers linked to $351M Bitget crypto theft shows that the attackers are always hunting for the weakest link, whether that is an exchange's hot wallet or a bug buried in a device meant to be cold storage. The threat is not hypothetical. It is active, and it is evolving.

If you are a user who did everything right, this news is unsettling. You updated firmware, you verified addresses, you kept your seed phrase offline. And still, a bug you had no way of knowing about undid all of that. This is the uncomfortable truth about self-custody. It places the full weight of security on your shoulders, and you are only as safe as the code you trust. The same logic applies to the broader data ecosystem. We recently covered how AI Agents Shared User Images, Highlighting Data Security Concerns, where a lapse in a different kind of system led to unintended exposure. The common thread is that trust is a fragile thing, whether you are relying on a hardware wallet or a cloud-based AI agent. When the foundation cracks, the cost is measured in more than just money. It is measured in lost confidence.

So what do we tell a reader who asks, "What should I do now?" First, do not panic and abandon hardware wallets altogether. That would be an overreaction. The concept of cold storage remains sound. But treat this as a wake-up call to diversify your approach. Do not keep all assets in a single device. Research how the specific vulnerability works, and apply any patches or mitigations immediately. Monitor wallet activity closely for a while. More importantly, question the assumption that any single layer of defense is enough. The Protecting Your Data: Kiteworks Advises Temporary Server Shutdown story shows that even when a threat is credible, the response is often reactive. You need to be proactive.

The specific detail to watch is whether the bug is a one-off flaw or a symptom of a deeper issue in the firmware design. If it is the latter, the entire industry needs to rethink how it audits code. For now, the takeaway is simple. $130 million is not a rounding error. It is the price of complacency. Ask yourself if you have a plan for the day your wallet does not work as promised. If the answer is no, that is where you start.

From TechCrunch

A security vulnerability in the cryptocurrency hardware wallet Coldcard is allowing hackers to drain the crypto from victims’ wallets. The total losses amount to more than $130 million, according to blockchain-monitoring firms.

Read the original at TechCrunch