Hackers exploited a vulnerability in the Coldcard cryptocurrency hardware wallet, draining more than $130 million from users’ accounts, TechCrunch reports. The breach was discovered in the device’s firmware, which was designed to keep private keys offline.
According to blockchain‑monitoring firms, the total losses exceed $130 million. TechCrunch notes that the flaw allows attackers to manipulate transaction data on the device, effectively bypassing its intended security. Coldcard has not yet issued a public statement or released a fix.
Hardware wallets are intended to provide the highest level of security for digital assets, so this incident highlights the risks posed by software bugs even in offline devices.