Coldcard Wallet Exploit Highlights Risks of Trusting Old Firmware
Researchers at Galaxy Research have traced a major cryptocurrency theft to a vulnerability introduced in a March 2021 firmware update for the Coldcard hardware wallet. The exploit has resulted in an estimated $116 million in stolen Bitcoin across affected users worldwide, with Canadian holders accounting for 25% of all attributable losses.
Hardware wallets are often marketed as one of the safest ways to store cryptocurrency because they keep private keys offline. However, this incident shows that even offline devices depend on trustworthy software updates. A flaw introduced years earlier in a firmware release went undetected long enough for attackers to exploit it at scale, underscoring how supply-chain and update-related vulnerabilities can undermine even well-regarded security tools.
While this case centres on cryptocurrency holders, the lesson applies broadly to any business relying on specialised hardware or firmware for security purposes. Vendors' update histories, patch transparency, and incident disclosure practices matter just as much as the device's reputation at launch.
Key Takeaway: Before trusting any hardware security device with valuable assets, check the vendor's track record on firmware security and keep an eye on advisories for known vulnerabilities.