Coinkite's Coldcard Firmware Exploited for $130M in Estimated Losses
Hackers have exploited a vulnerability in Coinkite's Coldcard firmware, resulting in estimated losses exceeding $100 million. Researchers verified the theft of 1,596 BTC from approximately 7,300 addresses across three coordinated attack waves.
According to Galaxy Research, including suspected but unconfirmed incidents could lift total losses to around $130 million. Coinkite declined to confirm this estimate due to its privacy-first design and lack of customer data.
The firm stated that its immediate focus is on helping affected customers and providing real-time updates through its public blog. An industry-wide AI-assisted security audit has already identified several critical bugs across crypto software systems.
In response to the incident, US spot Bitcoin ETFs saw $620 million in cumulative inflows as of Aug. 6, while daily active addresses increased to about 980,000, their highest level since December 2024, according to Glassnode.