How a bug in Coldcard’s code went unnoticed for years, leading to $100 million in hacked funds
A critical software vulnerability hidden within Coldcard's firmware went undetected for several years before being exploited, resulting in approximately $100 million in stolen cryptocurrency funds, according to a report published by CoinDesk. The bug, embedded in the hardware wallet manufacturer's codebase, allowed malicious actors to compromise private keys and drain user wallets without triggering standard security alerts.
Coldcard, produced by Coinkite, is widely regarded as one of the most security-focused hardware wallets available in the market, popular among Bitcoin maximalists and institutional holders who prioritize self-custody solutions. The device's reputation for open-source transparency and air-gapped operation had made it a preferred choice for users storing significant amounts of cryptocurrency. Despite regular audits and an active developer community, the flaw reportedly evaded detection across multiple firmware versions and update cycles.
The incident raises serious questions about the reliability of hardware wallet security models and the limitations of open-source auditing in practice. For the broader crypto industry, the breach underscores that even devices specifically engineered for cold storage are not immune to software-level vulnerabilities, potentially shaking consumer confidence in self-custody products at a time when hardware wallet adoption has been growing steadily.
Observers will be watching for Coldcard's official response, including details on the scope of affected devices, potential compensation mechanisms for impacted users, and what changes will be implemented in future firmware releases to prevent similar vulnerabilities.
Source: CoinDesk