← News·Markets · Digital AssetsMarkets

Hardware wallet exploit drains more than $130 million from Coldcard users

A security vulnerability in the Coldcard hardware wallet is being actively exploited, with blockchain monitoring firms attributing more than $130 million in losses to the attack as hackers drain cryptocurrency directly…

NM
NewsMV Markets Desk
3 min read
4 August 2026Markets desk
Share this dispatch

Key takeaways

  • A security vulnerability in the Coldcard hardware wallet is being actively exploited, with blockchain monitoring firms attributing more than $130 million in losses to the attack.
  • The flaw sits inside the Coldcard device itself, not in a connected service or a phishing scheme, so the wallet's offline design provided no protection.
  • Coldcard's maker is a private company, so no publicly traded ticker is directly in focus.
  • Because air-gapped hardware wallets require deliberate user action to install firmware updates, the gap between a patch's release and its widespread adoption can be lengthy.
  • The next milestones are a confirmed fix from Coldcard's maker and verification from blockchain monitoring firms that the exploit vector has been closed.

A security vulnerability in the Coldcard hardware wallet is being actively exploited, with blockchain monitoring firms attributing more than $130 million in losses to the attack as hackers drain cryptocurrency directly from victims' devices. Coldcard is purpose-built for offline self-custody, keeping private keys isolated from internet-connected systems. That design provided no protection once the bug was present in the device itself.

The breach in plain terms

Hardware wallets earn their position in a self-custody setup by keeping private keys off the internet. The device signs transactions locally. Nothing sensitive crosses a network connection. Users who distrust exchanges or centralized custodians rely on exactly this architecture as a step above software wallets and a full exit from counterparty risk.

The exploit breaks that premise at its base. The vulnerability sits inside the device itself, not in a connected service or an upstream phishing scheme. Coldcard's maker is private, so no publicly traded ticker is directly in focus. Blockchain monitoring firms are the sourced authority on the $130 million figure. The source framing, "bug in offline hardware wallets," identifies the attack surface as the defining feature of this product category rather than a lapse in user behavior.

That distinction matters. A device-layer flaw is harder to dismiss as user error.

What to watch

Hardware wallet firmware updates are not automatic. Devices designed to operate air-gapped do not receive patches the way internet-connected hardware does. The update process requires deliberate user action, which means the window between a patch being released and a patch being widely applied can stretch considerably across a user base that, by design, stays offline.

The next concrete milestones are a confirmed fix from Coldcard's maker and verification from the blockchain monitoring firms currently tracking outflows that the exploit vector has been closed.

Related reading

Categorycrypto

Filed via techcrunch.com

Keep reading

More from the markets desk

Frequently asked

How much money has been lost in the Coldcard exploit?

Blockchain monitoring firms attribute more than $130 million in losses to the attack.

Why didn't Coldcard's offline design stop the attack?

The vulnerability sits inside the device itself rather than in a connected service or phishing scheme, so keeping private keys offline offered no protection once the bug was present.

Who is the source for the $130 million figure?

Blockchain monitoring firms are the sourced authority on the $130 million loss figure.

Why can hardware wallet vulnerabilities take a long time to fix across users?

Air-gapped devices do not receive automatic patches and require deliberate user action to update, so the window between a patch's release and its widespread application can stretch considerably.

What should observers watch for next?

A confirmed fix from Coldcard's maker and verification from the blockchain monitoring firms tracking outflows that the exploit vector has been closed.