Coldcard Urges Users to Move Bitcoin as Ongoing Exploit Linked to $114M in Losses

AI Market Summary
Coldcard's warning that an active exploit has reportedly drained ~$114M from certain hardware wallets, with no patch yet, undermines confidence in Bitcoin self-custody security assumptions. The lack of public technical details increases uncertainty for holders and could trigger precautionary fund migrations, elevating on-chain activity and operational risk. While not a protocol issue, the event can weigh on sentiment by highlighting device-layer and supply-chain vulnerabilities.
Impact level
● Medium
Affected assets
BTC/USDT+0.67%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Bitcoin's hardware wallet market is grappling with an unusually severe incident. Coldcard's maker says an exploit is still actively draining funds from certain devices, with losses estimated at about $114 million. As of Tuesday, the vulnerability had not been patched, and the company is urging users to move bitcoin off any potentially affected hardware immediately, according to the original report. The issue has been building for weeks among Coldcard owners. Reports suggest the attack targets specific firmware versions and hardware setups, defeating the security checks that typically make hardware wallets central to self-custody. Unlike phishing or seed phrase exposure, this appears to be a direct compromise at the device level, calling into question the core premise that keeping keys offline is inherently safer. If the vulnerability is firmware-specific, it would explain why some devices appear unaffected while others continue to be emptied. Coldcard has not publicly identified which models are exposed, how the exploit functions, or when a fix may arrive. That restraint may be intended to avoid providing attackers a roadmap. It also leaves users without clear guidance beyond moving funds. Coldcard has long been popular with Bitcoin-focused users for its air-gapped approach and Bitcoin-only firmware. The absence of a patch timeline has fueled speculation that the underlying cause could be complex, potentially involving supply-chain risk or a flaw introduced in an earlier firmware update. Hardware wallet vulnerabilities are not unprecedented—devices from Ledger and Trezor have faced past incidents—but the reported scale in this case stands out. The episode highlights a broader self-custody dilemma: it reduces exchange risk, yet places heavy technical responsibility on individuals who may not be equipped to assess whether their device is trustworthy. Moving funds off a hardware wallet can also create new exposure. For many users, the fastest alternative is a hot wallet on a phone, which may increase the attack surface. The decision becomes a tradeoff between a confirmed, active threat and the risks of a less hardened environment. Key questions remain unresolved, including whether the exploit can be triggered remotely, requires physical access, or relies on weaknesses in companion software used during signing. Even a firmware update may be insufficient if the compromise extends to hardware or bootloader components. A full technical postmortem is expected only after the situation is contained, which could take days or weeks. Recovery prospects for affected users remain uncertain. While Bitcoin's public ledger can aid tracing, pseudonymity and jurisdictional hurdles often limit enforcement, and restitution for individual victims has historically been rare. Market impact—including potential fallout for hardware wallet demand among Bitcoin-native users—may depend largely on how quickly Coldcard delivers a fix and clearer disclosures. For now, the company's guidance is blunt: if you suspect your device is among those affected, treat it as compromised and move your bitcoin before you become part of the growing loss tally.