Regulation
Coldcard Hardware Wallet Exploit Drains Over $130 Million in Bitcoin
27 Aug 2026, 19:50
1 views
Admin
An attacker exploited a five-year-old firmware flaw in Coinkite's Coldcard device to systematically drain funds, marking the third-largest crypto hack of 2026.
<p>An attacker has drained more than $130 million in bitcoin from users of Coinkite's Coldcard hardware wallet by exploiting a firmware vulnerability that had gone undetected for roughly five years, according to blockchain-monitoring firms tracking the incident.</p>
<p>The exploitation began around July 30 and unfolded systematically, with the attacker leveraging the long-standing firmware flaw to drain affected devices over an extended period rather than in a single coordinated sweep. Blockchain analytics firms tracking the incident have classified it as the third-largest crypto hack of 2026, pushing the year's cumulative hack and exploit losses past $1.2 billion across 276 separate incidents tracked so far.</p>
<p>Coldcard has long been marketed within the Bitcoin community as one of the more security-focused hardware wallet options, built specifically around air-gapped signing and a minimal attack surface compared to general-purpose hardware wallets that support many blockchains. A five-year-old firmware flaw surfacing in a device with that security reputation is likely to raise uncomfortable questions for users who chose Coldcard specifically for its narrower, security-first design philosophy.</p>
<p>The incident adds to what analytics firm TRM Labs has described as 2026 shaping up to be crypto's most-hacked year on record, with AI-assisted attack techniques increasingly used by threat actors to identify and exploit vulnerabilities faster than in prior years. TRM reported that AI adoption across crypto crime rose roughly 40% year-over-year, and that the past six months alone saw 207 separate hacking incidents -- the most ever recorded in any half-year period the firm has tracked.</p>
<p>Coinkite has not detailed the specific technical nature of the exploited flaw or whether a firmware patch has been issued to close it. Users of the affected devices are advised to check for firmware updates directly from Coinkite and to treat any bitcoin holdings on unpatched Coldcard devices as potentially at risk until the vulnerability is confirmed resolved.</p>
<p>The exploit is the latest reminder that hardware wallets, while significantly more secure than software-based custody in most threat models, are not immune to serious vulnerabilities -- underscoring the importance of keeping device firmware current rather than treating hardware wallet security as a one-time setup decision.</p>
<p>The exploitation began around July 30 and unfolded systematically, with the attacker leveraging the long-standing firmware flaw to drain affected devices over an extended period rather than in a single coordinated sweep. Blockchain analytics firms tracking the incident have classified it as the third-largest crypto hack of 2026, pushing the year's cumulative hack and exploit losses past $1.2 billion across 276 separate incidents tracked so far.</p>
<p>Coldcard has long been marketed within the Bitcoin community as one of the more security-focused hardware wallet options, built specifically around air-gapped signing and a minimal attack surface compared to general-purpose hardware wallets that support many blockchains. A five-year-old firmware flaw surfacing in a device with that security reputation is likely to raise uncomfortable questions for users who chose Coldcard specifically for its narrower, security-first design philosophy.</p>
<p>The incident adds to what analytics firm TRM Labs has described as 2026 shaping up to be crypto's most-hacked year on record, with AI-assisted attack techniques increasingly used by threat actors to identify and exploit vulnerabilities faster than in prior years. TRM reported that AI adoption across crypto crime rose roughly 40% year-over-year, and that the past six months alone saw 207 separate hacking incidents -- the most ever recorded in any half-year period the firm has tracked.</p>
<p>Coinkite has not detailed the specific technical nature of the exploited flaw or whether a firmware patch has been issued to close it. Users of the affected devices are advised to check for firmware updates directly from Coinkite and to treat any bitcoin holdings on unpatched Coldcard devices as potentially at risk until the vulnerability is confirmed resolved.</p>
<p>The exploit is the latest reminder that hardware wallets, while significantly more secure than software-based custody in most threat models, are not immune to serious vulnerabilities -- underscoring the importance of keeping device firmware current rather than treating hardware wallet security as a one-time setup decision.</p>