
A five-year-old security vulnerability has reportedly enabled attackers to steal nearly $89 million in bitcoin from thousands of hardware wallets. The breach stems from a flaw identified in firmware released for Coldcard devices in 2021, which allowed hackers to siphon funds across three distinct waves of attacks.
According to findings cited by CoinDesk and Galaxy Research, the losses totalled 1,367 bitcoin originating from 4,585 addresses. While each wave is likely attributable to a single attacker, it remains unclear whether one individual orchestrated all incidents. This exploit distinguishes itself from typical cryptocurrency thefts involving exchange breaches or phishing schemes that steal private keys directly.
Normally, hardware wallets are considered secure because they store cryptographic keys on offline devices never connected to the internet. However, researchers discovered that this specific firmware flaw made seed phrases susceptible to guessing. Seed phrases consist of a large number intended to be unguessable but were compromised by the vulnerability, allowing attackers to reconstruct private keys without ever physically accessing the wallets.
Security companies warn that additional wallets may fall victim as owners cannot definitively determine if their seeds were generated on vulnerable firmware versions. Coldcard acknowledged the issue publicly and advised users migrating to new keys to proceed with care rather than rushing the process. The company noted that hasty migration could create immediate risks exceeding those of the original vulnerability.
This incident represents one of several recent security failures in the cryptocurrency sector. Last weekend, Singapore-based stablecoin payments firm Triple-A suffered a breach affecting its internal assets but not customer funds. Similarly, blockchain network WEMIX announced an attacker had compromised ownership of its WEMIX$ stablecoin. Earlier this month, wallet provider SecondFi stated it would wind down operations following a breach that allowed thieves to steal $2.4 million.
The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.
This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.
The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.






