Coldcard Wallet Exploit Drains $70 Million in Bitcoin
A firmware bug in Coldcard hardware wallets allowed attackers to steal approximately $70 million in Bitcoin from self custody users.

BTCcoinbeat.news
BTC/USD live chart
LIVEResearchers at Galaxy Digital report that roughly $70 million worth of Bitcoin has been drained from users of the popular Coldcard hardware wallet. The security breach stemmed from a firmware bug that severely compromised the randomness used to create secret recovery phrases. According to the onchain analysis, attackers managed to sweep the vast majority of the stolen funds in less than an hour.
The stolen funds mostly came from individual self custody accounts rather than large institutions or exchanges. Coinkite, the team behind Coldcard, issued a full apology and took accountability for the firmware issue. The company released emergency updates to fix the vulnerability and remove the faulty software fallback path.
Updating the firmware alone will not protect existing wallets. Users who generated recovery phrases on vulnerable software must move their Bitcoin to a freshly generated seed phrase immediately. Security experts advise all Coldcard owners to check their device versions and complete the migration process as soon as possible to protect their assets.
Prices update live from CoinMarketCap. Market data, not financial advice.
Market sentiment
Be the first to react
▍Comments (0)
No comments yet. Start the conversation!



