Loading prices…
🩸BEARISH

Coldcard Supply-Chain Attack Drains 1,000+ BTC Wallets, $71M Lost

The figure is roughly twice the early read on the incident and lands Coldcard inside a growing supply-chain risk tier no Bitcoin custodian can ignore.

More than 1,000 Bitcoin wallets have been confirmed compromised in the Coldcard hardware-wallet incident, with losses now estimated at $71 million, roughly double the figure cited in early reporting on the breach.

Why it matters

Coldcard markets itself to the high-security end of the Bitcoin custody stack, including air-gapped signing, multisig workflows and a reputation among long-term holders. A supply-chain compromise that hits 1,000+ wallets at once reframes a niche hardware failure as a custody-class risk. If the malicious firmware reached devices through a genuine vendor channel rather than user-side phishing, the trust boundary shifts from "did the user get tricked" to "did the device ship compromised," and that is the question every institutional cold-storage team is now reviewing.

Market impact

Bitcoin's price has not shown a measurable reaction on the headline, which is consistent with how supply-chain incidents in this segment have priced in historically: impact concentrates in the affected vendor, competitors offering migration paths, and the broader perception of self-custody risk premium. Watch for firmware guidance from Coldcard, wallet-migration announcements from competitors, and any follow-up attribution that clarifies whether the breach crossed into retail devices or stayed inside a specific batch or distribution channel.

Related tokens
$BTC

Frequently asked questions

  1. How many Bitcoin wallets were affected in the Coldcard incident?

    More than 1,000 wallets were confirmed compromised, with losses now estimated at $71 million, roughly double the figure cited in early reporting on the breach.

  2. Why is the Coldcard breach described as a supply-chain attack?

    The framing follows from the scale and reach of the compromise. If malicious firmware reached devices through a genuine Coldcard distribution channel rather than user-side phishing or tampered imports, the trust boundary shifts from the holder's behavior to the device's factory state.

  3. How has Bitcoin's price reacted to the Coldcard news?

    Bitcoin has not shown a measurable price reaction on the headline, consistent with how supply-chain incidents in this segment have historically priced in. Impact concentrates in the vendor and competitors rather than spot price.

  4. Who is most at risk from this Coldcard compromise?

    Holders using affected Coldcard devices for self-custody, including long-term holders and small institutional desks that prioritized Coldcard for air-gapped signing and multisig workflows. The risk scales with how widely a compromised firmware version was distributed.

  5. What should affected Coldcard users do now?

    Watch for official firmware guidance and wallet-migration instructions from Coldcard. Until attribution clarifies whether the breach was confined to a specific batch or distribution channel, moving funds to a clean device or to a non-Coldcard signer is the conservative move.

Source attribution
Aggregated from CoinTelegraph · Verified · Last refreshed 1h ago
Open original →