Bitcoin hardware wallet maker destroys some inventory after more than $88 million stolen
The company behind a popular hardware wallet for bitcoin owners was forced to destroy part of its inventory after thieves siphoned more than $88 million from customers through a firmware vulnerability.
Canadian company Coinkite said it destroyed its remaining inventory of Coldcard devices following reports last week that customers were being robbed of their bitcoin. The devices are used to safely store bitcoin offline instead of on an exchange. Last week, the company confirmed that a vulnerability previously discovered in March 2021 is now being used to breach accounts.
Cybersecurity firm Galaxy Research said the hackers behind the campaign have stolen at least 1,367.05 BTC, worth about $88.6 million, from 4,585 addresses.
In a statement on Sunday, Coldcard said it has been working with customers to move funds.
“If you have an affected device, please do not dispose of it. It may become essential if funds are recovered. Our legal team will coordinate as warranted with law enforcement across multiple jurisdictions to support efforts in identifying those responsible,” the company said.
“We destroyed our remaining COLDCARD inventory manufactured with the vulnerable firmware, and shipment was halted when the vulnerability was confirmed.”
Coldcard also released a patched version of the firmware that it says prevents the issue going forward.
In a follow-up message, the company said the devices have high-security system locks that cannot be upgraded until a user initializes it. The company cannot ship units “with affected firmware and risk users missing the upgrade.”
“The safest action was to destroy all the affected inventory and ship only those with the new fixed firmware,” they explained.
The company did not respond to requests for comment about whether it will compensate victims.
Blockchain analysis firm Chainalysis said two of the biggest victims of the Coldcard exploit lost a combined $4 million and dozens of bitcoin holders came forward on social media to discuss their losses.
“Our analysis of the… Coldcard hack reveals that the attacker hit high-value wallets (including a $1.8M victim) early in the sweep. This pattern suggests that the attacker studied the victim wallet population before proceeding,” Chainalysis said.
“Because the attacker prioritized the biggest wallets, the cumulative value stolen skyrocketed to roughly $30 million in just the first 10 minutes.”
The FBI declined to comment on whether they are investigating the campaign.
A senior official at Coinkite blamed the incident in part on artificial intelligence-assisted code reviews, which they believe allowed the cybercriminals to “find latent bugs at a speed that is outpacing even the industry’s most seasoned experts.”
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



