News

Critical Vulnerability in Coldcard Hardware Wallets Enables $130M+ in Crypto Thefts

A significant security vulnerability in Coldcard hardware wallets has resulted in more than $130 million in cryptocurrency losses, blockchain monitoring firms have reported.

The exploit targets a weakness in how the hardware wallets handle the initial setup process. When a wallet's seed phrase—the critical recovery key that controls access to cryptocurrency holdings—is potentially exposed during setup, attackers can leverage this vulnerability to drain the wallet remotely.

Hardware wallets like Coldcard are designed to keep cryptocurrency keys offline, providing a layer of security against online threats. However, this incident highlights how vulnerabilities in the setup and initialization phase can undermine the security assumptions of "cold" storage.

Blockchain security researchers have been tracking the stolen funds, which have been moved through various addresses. Coldcard has not yet issued a public statement regarding the vulnerability or recommended actions for affected users.

Users of Coldcard wallets are advised to verify their setup process was conducted securely and to consider whether their seed phrases may have been exposed. The incident serves as a reminder that even hardware-based security requires careful attention to the entire security chain, from initial setup through daily use.

Sources