Historic Hardware Wallet Hack: $112M in Bitcoin Stolen via Coldcard Firmware Flaw
A critical vulnerability in Coldcard hardware wallet firmware, present since March 2021, has been exploited to drain more than 1,778 Bitcoin—worth an estimated $112.7 million—from over 8,600 individual wallet addresses. This makes it the largest hardware wallet compromise on record.
Hardware wallets are widely trusted as one of the safest ways to store cryptocurrency because they keep private keys offline, away from internet-connected devices. This incident shows that even offline, 'cold storage' devices can carry hidden flaws in their firmware that go unnoticed for years, giving attackers a long window to exploit victims once the vulnerability is discovered.
For Australian small businesses that hold or accept cryptocurrency payments, this serves as a reminder that no storage method is entirely risk-free. Firmware and software updates should be applied promptly, and businesses should monitor vendor security advisories closely, especially for devices tied directly to financial assets.