Coldcard Hardware Wallet Firmware Exploit Reportedly Drains Up to $100M in Bitcoin
A firmware exploit affecting the Coldcard hardware wallet has reportedly been used to drain as much as $100 million worth of Bitcoin, according to Financial Press. The incident coincided with a spike in Bitcoin active addresses to 980,000, though the exact relationship between the two events was not detailed in the source report.
Hardware wallets are often marketed as one of the safest ways to store cryptocurrency because they keep private keys offline. However, this incident is a reminder that even offline devices depend on firmware that can contain vulnerabilities, and attackers who find flaws in that firmware can potentially bypass the protections users rely on. The event is also said to be pushing some investors toward regulated custody solutions as an alternative to self-managed storage.
While this story centres on individual crypto holders rather than businesses, Australian SMBs that hold cryptocurrency as part of treasury reserves, accept crypto payments, or use hardware wallets for company funds should take note. Any device connected to financial assets, digital or physical, needs its firmware kept up to date and sourced only from verified vendors.