Industry News

Coldcard Hardware Wallet Flaw Exploited by 15 Hackers, $130M in Bitcoin Stolen

Dailycoin · 5 Aug 2026
Key Takeaway If your business relies on hardware security devices such as tokens or wallets, keep their firmware updated and monitor vendor security advisories closely.

Galaxy Research has revealed that a firmware vulnerability in Coldcard, a popular hardware wallet used to store cryptocurrency offline, is being actively exploited by multiple threat actors. According to the research, at least 15 separate hackers have taken advantage of the flaw, collectively draining an estimated $130 million in Bitcoin from affected wallets, with the total continuing to grow.

Hardware wallets are often marketed as one of the safest ways to store digital assets because they keep private keys offline, away from internet-connected devices. This incident highlights that even offline, purpose-built security devices can contain firmware flaws that attackers can exploit at scale once discovered, and that multiple independent actors can move quickly to capitalise on the same vulnerability.

While this case centres on cryptocurrency holders rather than typical business systems, it is a reminder for any organisation using hardware security devices, tokens, or specialised firmware-based equipment that these products require the same vigilance as software: monitoring vendor advisories, applying firmware updates promptly, and not assuming a device is safe simply because it is offline.

Summarised by CISO AI from Dailycoin. We link back to every original so you can read it yourself.