What happened
Attackers exploited a firmware flaw dating back to a 2021 Coldcard release, draining roughly 1,367 bitcoin, worth close to $89 million, from more than 4,500 wallet addresses across three separate waves of theft reported through August 2. According to Galaxy Research and reporting from CoinDesk, the flaw made the wallets' seed phrases, the cryptographic backup codes meant to be effectively unguessable, predictable enough for attackers to reconstruct private keys and steal funds without ever physically accessing the hardware itself. That is notable because hardware wallets like Coldcard are marketed specifically as offline, tamper-resistant storage, safe from exactly this kind of remote compromise. Coldcard has acknowledged the issue and is urging affected users to migrate their funds, while cautioning that a rushed migration can itself introduce new risk.
Why it matters for your business
Most small businesses in the DMV are not sitting on bitcoin, but the underlying lesson applies to any hardware you rely on for security: a flaw introduced in a 2021 firmware release sat undetected for roughly five years before attackers found and exploited it at scale. That is true of routers, point-of-sale terminals, security cameras, and payment hardware too, not just crypto wallets. If your business has not checked the firmware version on its network and payment hardware recently, or if a vendor issues a firmware update and your team treats it as optional, this is a reminder that offline and hardware-based do not automatically mean immune.
What to do about it
- If your business holds cryptocurrency, confirm your wallet firmware is current before moving funds
- Ask hardware vendors, including routers, POS systems, and security cameras, how long they support firmware updates and how they disclose vulnerabilities
- Put a recurring calendar reminder to check firmware versions on critical hardware, not just software
