News
Public · Published
Coldcard Hack: $89M Drained From Hardware Wallets by a 5-Year-Old Bug
A five‑year‑old firmware bug in Coldcard hardware wallets allowed an attacker to drain 1,367 BTC, worth about $89 million, from 4,585 wallets without phishing or user error.
Published:
Updated:
What happened
A five‑year‑old firmware bug in Coldcard hardware wallets allowed an attacker to drain 1,367 BTC, worth about $89 million, from 4,585 wallets without phishing or user error.
Confirmed
Global impact / market context
The hack demonstrates that hidden software bugs can cause large financial losses, prompting investors to reassess the safety of storing crypto in hardware wallets and consider diversification of custody methods.
Analyst inference
The incident shows that even well‑reviewed crypto hardware can contain hidden flaws, reminding investors that security risks can affect the broader digital‑asset market and may influence confidence in hardware wallets.
Analyst inference
What to watch
- Updates from Coldcard on firmware patches and the timeline for rolling them out to all devices. Proposed
- Responses from other hardware‑wallet manufacturers about reviewing their code for similar long‑standing vulnerabilities. Proposed
- Potential regulatory scrutiny of hardware‑wallet security standards and any new compliance requirements for crypto custodians. Analyst inference
Affected assets
- BTC — Bitcoin