$89M in Bitcoin Gone: Coldcard's Firmware Flaw Just Shook Every Hardware Wallet Owner
Hackers quietly drained $89 million in Bitcoin from thousands of Coldcard wallets after discovering a critical firmware vulnerability, and the crypto community's most trusted storage assumption just collapsed overnight.
Coldcard has long been the gold standard for self-custody Bitcoin storage. Favored by maximalists, privacy advocates, and serious holders, it carried a reputation built on years of open-source scrutiny and battle-tested security. That reputation is now in crisis.
What Actually Happened
Attackers exploited a flaw embedded in Coldcard's firmware, the low-level software that controls how the device processes and signs transactions. The nature of the vulnerability allowed them to compromise wallets at scale, hitting thousands of individual holders in what appears to be a coordinated, surgical attack. This was not a phishing campaign. This was not user error. The device itself was the entry point.
The result: $89 million in Bitcoin moved out of wallets that users believed were completely air-gapped from the internet and, therefore, untouchable.
The Uncomfortable Truth Hardware Wallet Believers Don't Want to Hear
The self-custody community has spent years arguing that hardware wallets eliminate counterparty risk. That argument still holds in theory. But theory just got stress-tested at $89 million in real losses, and it failed.
Firmware is code. Code has bugs. And bugs in air-gapped devices are arguably more dangerous than bugs in software wallets because users apply far less scrutiny to them. The assumption of physical security creates complacency, and complacency is exactly what attackers exploit.
Crypto Briefing notes that this incident may push some holders back toward centralized exchanges for Bitcoin storage, a shift that would represent a significant psychological reversal for the self-custody movement. That is not a comfortable outcome for anyone who spent the last two years screaming "not your keys, not your coins" after the FTX collapse.
What You Should Do Right Now
If you hold Bitcoin on a Coldcard device, treat this as urgent. Check Coldcard's official channels immediately for firmware patch information. Do not sign any transactions until you have confirmed your firmware version is not affected. Consider moving funds to a verified clean wallet while the scope of the vulnerability is still being assessed.
More broadly, this is a reminder that no storage solution is permanently risk-free. Diversifying custody methods, staying current on firmware updates across all hardware devices, and monitoring exploit disclosures from security researchers are no longer optional habits. They are survival basics.
The Bitcoin you hold is only as secure as the last time you checked. Check now.