Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen

The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.
Canadian company Coinkite said it destroyed its remaining inventory of Coldcard devices following reports last week that customers were being robbed of their bitcoin. The devices are used to safely store bitcoin offline instead of on an exchange. Last week, the company confirmed that a vulnerability previously discovered in March 2021 is now being used to breach accounts.
Cybersecurity firm Galaxy Research said the hackers behind the campaign have stolen at least 1,367.05 BTC, worth about $88.6 million, from 4,585 addresses.
In a statement on Sunday, Coldcard said it has been working with customers to move funds.
“If you have an affected device, please do not dispose of it. It may become essential if funds are recovered. Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible,” the company said.
“We destroyed our remaining COLDCARD inventory manufactured with the vulnerable firmware, and shipment was halted when the vulnerability was confirmed.”
Coldcard also released a patched version of the firmware that it says prevents the issue going forward.
In a follow-up message, the company said the devices have high-security system locks that cannot be upgraded until a user initializes it. The company cannot ship units “with affected firmware and risk users missing the upgrade.”
“The safest action was to destroy all the affected inventory and ship only those with the new fixed firmware,” they explained.
The company did not respond to requests for comment about whether it will compensate victims.
Blockchain analysis firm Chainalysis said two of the biggest victims of the Coldcard exploit lost a combined $4 million and dozens of bitcoin holders came forward on social media to discuss their losses.
“Our analysis of the… Coldcard hack reveals that the attacker hit high-value wallets (including a $1.8M victim) early in the sweep. This pattern suggests that the attacker studied the victim wallet population before proceeding,” Chainalysis said.
“Because the attacker prioritized the biggest wallets, the cumulative value stolen skyrocketed to roughly $30 million in just the first 10 minutes.”
The FBI declined to comment on whether they are investigating the campaign.
A senior official at Coinkite blamed the incident in part on artificial intelligence-assisted code reviews, which they believe allowed the cybercriminals to “find latent bugs at a speed that is outpacing even the industry’s most seasoned experts.”
References in this story
- Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware engineering.block.xyz How a disabled hardware-RNG path and 32-bit reseed constrain entropy in affected COLDCARD firmware and expose generated secrets.
- Galaxy Research (@glxyresearch) on X x.com 🚨 A 3rd wave in what we suspect are hacks of Coldcard-generated addresses has been identified in which 207.7294 BTC has been drained. Our estimated observed size of the Coldcard hack is now 1,367.05 BTC (~$88.6m) across…
- COLDCARD (@COLDCARDwallet) on X x.com https://t.co/BmZF7BjKQr
- Coldcard Security Advisory blog.coinkite.com Funds from affected COLDCARD seeds are at risk if the seed lacks 50 independent, private dice rolls and the wallet lacks a strong, unique BIP-39 passphrase.
- COLDCARD (@COLDCARDwallet) on X x.com Why destroy affected inventory? COLDCARD has a series of high-security system locks. Once programmed, it cannot be re-upgraded until the user initializes it. We cannot ship units with affected firmware and risk users…
- Chainalysis (@chainalysis) on X x.com The two biggest victims of yesterday’s Coldcard exploit lost a combined $4 million. Chainalysis Reactor shows they had split their holdings across multiple independent wallets, likely trying to mitigate their risk of…
- Tim Lamb (@theretailbull) on X x.com I’ve had all my bitcoin stolen while away on holiday. It was on a Coldcard MK3. I was led to believe this was really secure. It was recommended by experts including @saifedean. I also had the seed on a metal plate…
- Adam Carson (@punk4307) on X x.com I lost 6.42 BTC overnight. A little over $400,000 at today’s price. I noticed it early this morning when I opened Wasabi and the balance immediately looked wrong. Then I saw the outgoing transactions. None of them were…
- nvk (@nvk) on X x.com https://t.co/N60cz5Yprl
- Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
- jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
- jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51



