Coldcard's Bitcoin wallets have suffered losses close to $114 million following a sharp increase in numerous small transactions. The unusual spike suggests targeted exploitation of a firmware vulnerability that affects certain Coldcard hardware wallets.

According to cybersecurity experts, attackers are leveraging this flaw to siphon off small amounts of Bitcoin repeatedly, bypassing typical security barriers without triggering immediate alarms. These micro-transfers accumulate to significant total losses, impacting a sizable portion of Coldcard users worldwide.

Firmware Vulnerability Sparks Widespread Theft

As detailed by security researchers, the vulnerability resides in the wallet's firmware, which fails to properly authenticate transaction signing in edge cases. This oversight allows malicious actors to authorize transfers without the user's explicit consent. The pattern of these thefts involves many small transfers rather than a few large ones, which makes detection and response more challenging.

Coldcard has acknowledged the issue and is reportedly working on a patch, but the scale of the compromise shows the risks of hardware wallet dependencies on firmware reliability. The incident highlights the importance of vigilance and possibly diversifying storage solutions while manufacturers improve their security protocols.

Such developments follow previous reports revealing firmware bugs can open doors to significant Bitcoin thefts. Users concerned about the safety of their funds are advised to monitor official updates and avoid unnecessary transactions until a fix is released.

This material is informational and should not be considered financial advice.