Future TechnologyFuture Technology
Security

A Firmware Flaw in a Hardware Wallet Just Cost Someone 70 Million Dollars

· 4 min read · By Future Technology

Key takeaways

  • A firmware flaw in Coldcard, a popular Bitcoin hardware wallet, was exploited to drain roughly 70 million dollars from a single holder
  • Hardware wallets are marketed as immune to remote theft because keys never touch an internet-connected device, but firmware itself is still software with bugs
  • The incident is a reminder to keep wallet firmware updated and to verify firmware sources before installing
  • Large holdings are increasingly a target regardless of how they are stored, cold or hot

Cold storage exists because keeping cryptocurrency keys on an internet-connected device is asking for trouble. A hardware wallet like Coldcard is meant to be the fix: the private key is generated and stored on a small offline device, and it never touches a computer or phone directly connected to the internet. That model just took a serious hit. A firmware flaw in Coldcard was exploited to drain around 70 million dollars in Bitcoin from a single holder.

Cold does not mean bug free

The uncomfortable truth is that a hardware wallet is still running software. Firmware is code, and code has bugs. Cold storage protects against remote network attacks, but it does not protect against a flaw in the device's own logic, and it does not protect against firmware that has been tampered with before it ever reaches the user. Once an attacker finds a way to exploit the firmware itself, the fact that the device was never connected to the internet stops being much of a defence.

Why it matters

Seventy million dollars from one incident is the kind of number that gets attention, but the practical lesson applies at any holding size. Keep hardware wallet firmware updated the moment a security patch is released, only install firmware from the manufacturer's verified source, and treat a hardware wallet as a device that needs maintenance, not a set-and-forget vault. For very large holdings, spreading funds across multiple devices and using multi-signature setups limits how much a single flaw can cost you.

Sources and further reading below.

Browse all Cybersecurity stories →