A Major Vulnerability Has Appeared in the Coldcard Hardware Wallet! According to the latest data from Galaxy Research, about 1,719 $BTC (worth approximately $111 million) have been stolen due to this vulnerability. Galaxy has received reports from more than 250 victims. There are still more suspicious funds on-chain awaiting verification, and the total estimated losses may exceed $130 million.
Key takeaways:
1. Scope of impact: At present, there is no evidence that this vulnerability affects any other signing devices or wallets besides Coldcard Mk3, Mk4, Mk5, or Q. The impact is concentrated on the above devices running firmware versions released after March 17, 2021.
2. Key timeline: For firmware released before March 17, 2021, no records of the creation of stolen tokens have appeared on-chain. Users who used earlier firmware versions have not yet been found to be affected.
3. Fund tracking: Galaxy Research is continuously tracking the flow of stolen funds and advises affected users to promptly check the status of their assets.
Hardware wallets have long been regarded as one of the safest storage methods for crypto assets, but this Coldcard vulnerability incident is yet another warning: even offline storage devices cannot completely eliminate code-level security risks.
For users holding positions, it is recommended to immediately confirm the firmware version of your Coldcard device. If it is running firmware released after March 17, 2021, you should transfer your assets to brand-new cold wallet addresses that have never been exposed online as soon as possible. Also closely monitor official follow-up patch updates and vulnerability notices.
Safety matters—every step in using a cold wallet correctly is crucial, including offline mnemonic storage, trusted purchase channels for the device, and verifying signatures before upgrading firmware.
#Coldcard#HardwareWallet#BTC
Key takeaways:
1. Scope of impact: At present, there is no evidence that this vulnerability affects any other signing devices or wallets besides Coldcard Mk3, Mk4, Mk5, or Q. The impact is concentrated on the above devices running firmware versions released after March 17, 2021.
2. Key timeline: For firmware released before March 17, 2021, no records of the creation of stolen tokens have appeared on-chain. Users who used earlier firmware versions have not yet been found to be affected.
3. Fund tracking: Galaxy Research is continuously tracking the flow of stolen funds and advises affected users to promptly check the status of their assets.
Hardware wallets have long been regarded as one of the safest storage methods for crypto assets, but this Coldcard vulnerability incident is yet another warning: even offline storage devices cannot completely eliminate code-level security risks.
For users holding positions, it is recommended to immediately confirm the firmware version of your Coldcard device. If it is running firmware released after March 17, 2021, you should transfer your assets to brand-new cold wallet addresses that have never been exposed online as soon as possible. Also closely monitor official follow-up patch updates and vulnerability notices.
Safety matters—every step in using a cold wallet correctly is crucial, including offline mnemonic storage, trusted purchase channels for the device, and verifying signatures before upgrading firmware.
#Coldcard#HardwareWallet#BTC