Coldcard Exploit Exceeds $100M as Investigation Unravels Scope of Breach
A massive exploit targeting Coldcard hardware wallets has resulted in over $100 million worth of losses, with investigators still unraveling the full extent of the breach. The incident initially appeared to be a smaller-scale hack, but further investigation revealed that it involved more than 7,300 addresses and nearly 1,600 Bitcoin stolen.
The attackers' behavior suggests they prioritized consolidating funds rather than quickly liquidating them, with nearly 90% of the stolen coins remaining untouched. This pattern has helped investigators map attacker-controlled wallets and identify linked addresses, which are being shared with law enforcement and exchanges to prevent further exploitation.
The incident has raised questions about the security of hardware wallets and self-custody in Bitcoin, highlighting the need for better-designed wallets and independent entropy generators. In response, Coinkite released emergency firmware, paused shipments, and urged users to generate new seeds before moving funds.