Hackers are exploiting a software flaw in Coldcard hardware wallets to drain Bitcoin from thousands of supposedly secure accounts in an ongoing attack.
This breach is significant because Coldcard is regarded as one of the safest cold-storage solutions for Bitcoin. The attack undermines the core premise of hardware wallets, keeping private keys offline to prevent remote theft, and threatens user confidence in high-security storage.
The exploit targets a vulnerability within the Coldcard wallet software, which allowed attackers to bypass security measures and access funds. According to reports, the breach has affected more than 4,500 accounts [1].
Financial estimates of the total loss vary between major reporting outlets. The Hindu Business Line said $86 million [1] has been stolen. However, a summary from Bloomberg Television said the total stolen is more than $100 million [2].
Cold-storage devices are designed to keep cryptocurrency assets isolated from internet-connected devices. By identifying a flaw in the software, hackers were able to penetrate this isolation, effectively turning a "cold" wallet into a vulnerable target.
The attack is described as ongoing, meaning additional funds could be at risk if users do not take immediate action to secure their assets. Security experts have not yet provided a universal patch for all affected devices, though the focus remains on identifying the specific software flaw that enabled the drainage of funds [1], [2].
“Hackers are exploiting a software flaw in Coldcard hardware wallets to drain Bitcoin.”
This attack demonstrates that no single point of failure is truly eliminated, even in air-gapped hardware environments. When a vulnerability is found in a product marketed as 'the safest,' it forces a shift in the cryptocurrency industry toward multi-signature wallets and diversified storage strategies to mitigate the risk of a single software flaw causing total loss.



