Hackers Steal More Than $130 Million Through Bug in Coldcard Offline Hardware Wallets
NEW YORK, Aug. 5. More than $130 million in cryptocurrency has been stolen from Coldcard hardware wallet holders through a security vulnerability that remains active, blockchain-monitoring firms reported. Coldcard is sold as an offline, or cold-storage, device designed to hold private keys on hardware kept disconnected from the internet. The identified bug allows attackers to drain funds from those wallets despite that isolation.
Key takeaways
- More than $130 million in cryptocurrency has been stolen from Coldcard hardware wallet holders through a security vulnerability that remains active, according to blockchain-monitoring firms.
- Coldcard is marketed as an offline cold-storage device that holds private keys on hardware disconnected from the internet, but the bug allows attackers to drain funds despite that isolation.
- Blockchain-monitoring firms traced fund outflows from affected wallets and attributed the losses to exploitation of the bug, though the firms are not named individually.
- The $130 million figure represents a floor, and the total number of compromised wallets and any breakdown of stolen assets by cryptocurrency have not been reported.
- Coldcard's manufacturer has not been reported as issuing a public response, and no individual victims are named in the source material.
NEW YORK, Aug. 5. More than $130 million in cryptocurrency has been stolen from Coldcard hardware wallet holders through a security vulnerability that remains active, blockchain-monitoring firms reported. Coldcard is sold as an offline, or cold-storage, device designed to hold private keys on hardware kept disconnected from the internet. The identified bug allows attackers to drain funds from those wallets despite that isolation.
What blockchain monitors have found
Blockchain-monitoring firms have traced fund outflows from affected Coldcard wallets and attributed the losses to exploitation of the bug. The source identifies multiple firms monitoring the situation but does not name them individually. No breakdown of stolen assets by cryptocurrency has been reported.
The exploit and what it means for cold storage
Cold-storage hardware wallets rest on a specific security premise: private keys stored on an offline device cannot be accessed without physical control of that device. Coldcard is marketed on that assumption. A vulnerability enabling fund draining directly contradicts it. The source does not describe the technical mechanism of the exploit or what an attacker must do to trigger it.
What remains unreported
Coldcard's manufacturer has not been reported as having issued a public response to the vulnerability. The total number of compromised wallets is not specified. No individual victims are named in the available source material. The $130 million figure represents a floor; by how much losses have exceeded that threshold is not given.