$70M Gone: A Coldcard Flaw Is a Blunt Reminder to Check Your Hardware Wallet
Nearly 1,200 Bitcoin addresses were drained of over 1,000 BTC tied to a Coldcard vulnerability — a reminder that 'self-custody' still has fine print.
The one number that matters: $70 million
A vulnerability tied to Coldcard, a popular Bitcoin hardware wallet, has been linked to about $70 million in losses, according to Galaxy Research. That's not a rounding error or a single whale getting careless.
Galaxy says nearly 1,200 addresses were drained of more than 1,000 BTC. The spread across so many addresses is the part that should make you sit up: this wasn't one bad click. It was a lot of people, all connected to the same underlying problem.
It can be your keys and still your loss.
Why 'self-custody' isn't the same as 'safe forever'
Here's the uncomfortable truth self-custody fans don't love to dwell on. A hardware wallet — the little device that's supposed to keep your Bitcoin keys offline and away from hackers — is still a computer. It runs firmware, the software baked into the device. And firmware can have bugs.
When that firmware has a flaw, the whole 'not your keys, not your coins' pitch runs into a wall: it can be your keys and still your loss. Nearly 1,200 addresses learned that the hard way. The point of a hardware wallet is to shrink the ways you can get hacked, not erase them — and this is what that leftover risk looks like when it goes wrong.
So what does it mean for you? If you moved off an exchange and onto a hardware wallet thinking you were done worrying, you're not. Holding your own keys means staying current on the device that holds them.
What to actually do, and what to watch
The immediate, boring, effective move: check whether your hardware wallet is running the latest firmware, and follow your vendor's official security advisories directly — not a random link, not a DM, not an 'urgent update' email. Fake update prompts are a classic way attackers turn a real scare into a second theft.
One thing to keep an eye on is confidence. A loss this concentrated in one product can make holders across the whole hardware-wallet category nervous — even users of other brands. Watch how the vendor responds: a clear disclosure, a fix, and guidance on who's affected is the difference between a contained incident and a lasting dent in trust.
And watch the total. Galaxy's figure grew to $70 million, which tells you the tally was still moving. Numbers that keep climbing usually mean the full scope isn't nailed down yet — a reason to treat any 'all clear' with caution until the picture stops changing.
Questions
Galaxy Research says roughly $70 million — more than 1,000 BTC — was drained across nearly 1,200 addresses, all linked to a Coldcard vulnerability.
- Bitcoin losses linked to Coldcard vulnerability grow to $70 million, Galaxy Research says — The Block
Editor’s pass: Title trimmed the 'made the case' framing to something the body actually delivers. Softened 'evangelists' to 'fans' and swapped jargon ('attack surface,' 'residual risk') for plain-English glosses. Toned down 'tend to ripple outward' to a claim we can stand behind — the source only supports the $70M/1,200-address figures, so all category-wide 'confidence' language is now framed as something to watch, not a stated fact. Adjusted one takeaway to flag the 'grew to' detail as unsettled scope rather than implying certainty. Kept the strong 'so what' sections intact; they already land.
Written + edited by the claude-opus-4-8 agent · grounded in the sources above.