Intelligence
criticalVulnerabilityActive

Firmware vulnerability in popular Bitcoin hardware wallet results in $88M theft and inventory destruction

A firmware vulnerability in a widely-used Bitcoin hardware wallet enabled attackers to steal over $88 million from customers. The manufacturer has responded by destroying affected inventory, indicating either a supply-chain compromise or a defect severe enough to warrant complete product recall.

S
Sebastion

Affected

ColdCard (inferred from source URL)

A significant firmware vulnerability in a major Bitcoin hardware wallet has enabled theft of over $88 million from customers, prompting the vendor to destroy inventory as a containment measure. The theft mechanism exploited a firmware defect rather than a physical attack or social engineering, suggesting either a manufacturing-stage compromise or a critical logic error in the wallet's signing or key-management routines. The scale of financial loss and the vendor's decision to destroy stock indicate this vulnerability affects multiple device batches and poses ongoing risk to customer funds.

The resorting to inventory destruction as a remediation strategy is noteworthy. Hardware wallets are designed to be tamper-resistant, yet if the vulnerability persists at the firmware level across multiple production runs, the vendor may have concluded that replacement firmware alone is insufficient, either because the vulnerability cannot be patched post-delivery, or because customer trust in the affected batches is irrecoverable. This suggests a fundamental design or manufacturing flaw rather than a simple software bug.

Hardware wallet users are the primary affected population. Unlike software wallets, hardware devices are assumed to provide cryptographic isolation and secure key storage; a firmware vulnerability that enables fund theft directly contradicts this security model. Customers holding affected devices face immediate risk of key compromise and asset loss. The financial impact of $88 million across potentially thousands of users indicates widespread deployment and high customer vulnerability.

Defenders and institutional custodians using this wallet should immediately audit transaction histories, check for unauthorised key exports or signing operations, and consider key rotation to new, verified hardware. Organisations procuring hardware wallets should demand detailed post-incident forensics, proof of firmware integrity verification in their supply chain, and clarity on whether the vulnerability affects current production batches. Vendors should publish a detailed security advisory naming the vulnerability, affected firmware versions, and a verified patch or replacement procedure.

This incident underscores a critical blind spot in hardware security: supply-chain integrity and manufacturing verification are often weaker than the cryptography they protect. A $88 million theft from hardware wallets, which exist precisely to prevent such losses, suggests that vendor security practices around firmware signing, secure boot, and manufacturing controls merit immediate industry scrutiny. Until technical details emerge, the scope of the vulnerability and the root cause remain unclear, but the financial impact and inventory destruction confirm this is not a minor issue.

Sources