Coldcard Warns Bitcoin Hardware Wallet Users: Active Exploit Still Draining Funds
Coldcard, a maker of hardware wallets used to store bitcoin offline, has confirmed that a serious security flaw is still being actively exploited by attackers. The company says the vulnerability, which affects specific device models and firmware versions, has already contributed to roughly $114 million in stolen bitcoin.
Hardware wallets are typically marketed as a safer alternative to keeping cryptocurrency on exchanges or software wallets, since they store private keys offline. However, this incident shows that even offline devices can carry serious vulnerabilities if firmware issues go unpatched. Coldcard is urging all users of the affected models to move their bitcoin to a secure location as a precaution while the issue remains unresolved.
For Australian small businesses that hold or accept cryptocurrency as part of their operations, this is a reminder that hardware-based security tools are not automatically immune to compromise. Firmware updates and vendor security advisories should be treated with the same urgency as software patches on computers and servers.