In one of the most severe hardware security incidents in recent memory, a legacy vulnerability dating back to 2021 has led to a massive, multi-wave drain of Coldcard hardware wallets, leaving the Bitcoin community reeling.
Initial reports estimated losses near $70 million, but ongoing on-chain analysis confirms the total stolen capital has escalated close to $89 million, compromising more than 4,500 distinct Bitcoin addresses.
The Root Cause: A Legacy Firmware Oversight
Coldcard, produced by Canadian hardware maker Coinkite, has long been regarded as the gold standard for Bitcoin maxis and institutional self-custody due to its air-gapped architecture and security-focused design. However, security researchers have traced the breach to an unpatched flaw in legacy firmware code originally distributed in 2021.
The exploit allowed malicious actors to manipulate specific signing requests and key derivation paths under precise edge-case conditions, effectively bypassing the physical device's air-gap guarantees.
Key technical highlights surrounding the incident include:
-
Targeted Firmware Versions: The breach specifically exploited devices running unupdated 2021 firmware builds that omitted crucial entropy validation checks during signature generation.
-
Multi-Wave Execution: Rather than draining all targeted wallets simultaneously, the attacker executed automated script sweeps in distinct waves to evade early detection and automated monitoring alerts.
-
Air-Gap Limitations: Security analysts emphasize that while physical air-gaps protect against online network intrusions, they cannot prevent cryptographic flaws embedded within local signing logic.
On-Chain Impact and Funds Tracking
Blockchain analytics firms flagged suspicious mempool activity early Tuesday morning as hundreds of high-value wallets simultaneously broadcast sweeping transactions to consolidated mixer contracts and privacy-enhancing protocols.
The coordinated nature of the attack suggests a sophisticated adversary who spent months passively mapping vulnerable public keys exposed through past transaction histories before triggering the automated exploit.
"This incident highlights a harsh reality for self-custody: hardware security is only as strong as the cryptographic integrity of its firmware," noted a senior blockchain security analyst monitoring the transfers.
Community Response and Mitigation Steps
Coinkite has urged all Coldcard users to immediately verify their firmware versions and update to the latest official release via verified PGP-signed binaries.
For users holding funds on older devices:
-
Verify Firmware Version: Ensure your device is running the latest stable release directly from the official repository.
-
Transfer Funds if Compromised: If your wallet operated on 2021-era firmware, security specialists recommend migrating funds to a newly generated seed phrase created on fully patched hardware or a multi-signature setup.
-
Verify Signatures: Always check binary signatures when downloading hardware updates to prevent falling victim to secondary phishing attacks.
The Broad Implications for Bitcoin Self-Custody
The $89 million breach serves as a stark reminder that self-custody demands continuous vigilance. As the industry advances, protocol developers and security firms are calling for mandatory multi-institution code audits and more robust notification frameworks for critical hardware patches.

