A previously undisclosed vulnerability in Coldcard’s firmware allowed unauthorized access to cryptocurrency wallets, resulting in the exposure of funds exceeding $100 million, according to security researchers. The flaw, which remained unpatched for years, stemmed from a coding error in the wallet’s transaction verification process, enabling attackers to bypass security checks and extract private keys.
Coldcard, a leading provider of hardware wallets for Bitcoin and other cryptocurrencies, acknowledged the issue in a security advisory issued Sunday. The company stated that the bug was introduced in firmware versions released between 2019 and 2023 and affected an estimated 50,000 devices globally. While the vulnerability has since been patched in the latest firmware update, users who failed to update their devices remain at risk.
Security firm Halborn, which discovered the flaw, noted that the bug exploited a race condition in Coldcard’s code, allowing attackers to intercept and manipulate transaction signatures. The exploit required physical access to the device, raising concerns about supply-chain attacks or unauthorized access during transit. Halborn estimated that approximately 1.2% of affected wallets—totaling around $100 million in cryptocurrency—had already been drained by unidentified actors.
Coldcard urged users to immediately update their firmware to version 5.0.1 or later and to verify their wallet balances. The company also announced a reimbursement program for affected users, though the scope and eligibility criteria remain under review. The incident underscores the persistent security challenges in the cryptocurrency sector, where hardware wallets are often marketed as the gold standard for asset protection.
The revelation comes amid growing scrutiny of hardware wallet security, with several high-profile breaches in recent years highlighting vulnerabilities in even the most reputable products. Coldcard’s response, including its patch and reimbursement efforts, will likely shape industry best practices for addressing similar vulnerabilities in the future.



