Industry News

Coldcard Hardware Wallet Exploit Linked to Over $100 Million in Stolen Bitcoin

Crypto news · 4 Aug 2026
Key Takeaway If your business holds cryptocurrency, regularly check for security advisories and firmware updates from your hardware wallet provider, and don't assume offline storage is immune to vulnerabilities.

Galaxy Research has released new estimates on losses stemming from a security flaw in the Coldcard hardware wallet, a device used to store cryptocurrency offline for added protection. According to the report, confirmed attack waves have already resulted in the theft of 1,596 Bitcoin, with losses potentially rising to around 2,055 Bitcoin—nearly $130 million—if a suspected fourth wave of attacks is confirmed.

Hardware wallets are generally considered one of the safer ways to store digital assets because they keep private keys offline, away from internet-connected devices that are more vulnerable to hacking. However, this incident shows that even offline storage solutions can carry risks if a flaw exists in the device's design, firmware, or supply chain. While the exact nature of the exploit hasn't been detailed here, the scale of the losses highlights how attractive cryptocurrency wallets remain as targets for cybercriminals.

For Australian small businesses that hold or transact in cryptocurrency, this case is a reminder that no storage method is entirely risk-free, and staying informed about vendor security advisories is essential. Businesses should monitor for official communications from wallet manufacturers regarding firmware updates or security patches related to this incident.

Summarised by CISO AI from Crypto news. We link back to every original so you can read it yourself.