Roughly $40 million vanished from nearly 500 COLDCARD hardware wallets in less than half an hour, shaking confidence in self-custody solutions.
Details of the COLDCARD Breach
Reports reveal about 594 BTC were stolen due to a vulnerability tied to COLDCARD’s firmware version 4.0.0, dating back to March 2021. The exploit affected hundreds of wallets in just 25 minutes, making it one of the most significant hardware wallet hacks in recent memory. This incident contradicts the expectation that offline hardware wallets are the safest method to guard Bitcoin. The breach has amplified concerns about how software flaws can undermine device security, no matter how solid the hardware.
Industry Leaders Weigh In
Changpeng Zhao, CEO of Binance, responded on X by emphasizing that no wallet is entirely foolproof. He pointed out that even long-established hardware wallets can harbor bugs. He suggested spreading funds across multiple wallets to mitigate risk, but cautioned this isn’t a perfect solution either. His advice boiled down to staying informed and vigilant.
Samson Mow, head of JAN3, described this event as a harsh setback for Bitcoin holders who trusted self-custody over exchanges. Many victims had meticulously researched security before moving their coins off centralized platforms, making the loss especially painful. Mow urged affected users to document every detail and be wary of recovery scams that often target breach victims.
Strike CEO Jack Mallers also called on users to check their COLDCARD devices promptly to assess possible vulnerabilities.
This breach has triggered a surge in on-chain activity reminiscent of patterns seen after the FTX collapse’s ripple effects, with many small transfers as users scramble to secure funds noted in recent analysis.
This content is for informational purposes only and does not constitute financial advice.



