Coldcard Code Bug Sat Hidden for Years, Enabling $100M in Losses
A long-undetected flaw in Coldcard's firmware quietly exposed users to massive theft. Here's what traders need to know.
A software bug buried inside Coldcard's widely trusted hardware wallet code went undetected for years — and by the time anyone noticed, roughly $100 million in crypto had already been drained. That's the kind of headline that should make every self-custody advocate stop and reassess their setup right now.
Coldcard is considered one of the gold-standard devices for Bitcoin cold storage. It's marketed to serious holders who don't trust exchanges. The irony here is brutal: the very tool people used to escape custodial risk apparently carried its own silent vulnerability for an extended period without triggering any public alarm.
Read more Micron Could Generate $640B in Free Cash Flow by 2030, BofA Says →
The scale of the alleged losses — $100 million — puts this among the more significant hardware-wallet-related security failures in the industry's history. What makes it particularly stinging is the duration. Bugs that linger unnoticed for years suggest gaps in code auditing, testing pipelines, or responsible disclosure processes that the broader crypto security community will now have to confront seriously.
For active traders and long-term holders alike, the takeaway is immediate and practical. No device is zero-risk. Hardware wallets reduce attack surface dramatically compared to hot wallets, but they are not infallible. Firmware integrity checks, keeping devices updated, and diversifying storage across multiple solutions are no longer optional best practices — they're essential risk management. Treat your cold storage the way you treat position sizing: never go all-in on a single point of failure.
The full technical breakdown of exactly how the flaw worked and which wallet versions were affected is detailed by CoinDesk. Continue reading at CoinDesk.