The vulnerability existed in Coldcard firmware versions released since 2021. It allowed attackers to extract the seed phrase during the firmware update process or via an edge case in the signing flow. Most victims likely updated their firmware believing it was a security patch; the patch itself was the attack vector.
Hardware wallets remain the gold standard for self-custody, but this hack shows: (1) Firmware updates carry risk; (2) Older devices (5+ years) accumulate security debt; (3) 'Offline' doesn't mean 'unbreakable.' If you own Coldcard, update to v5.3.2 or newer immediately. If you used it before August, consider it compromised.
1) Update firmware to v5.3.2 (latest). 2) If your device is pre-update, treat seed phrase as compromised. 3) Move funds to new wallet immediately. 4) Invalidate old seed phrase. 5) Monitor for announcements from Coldcard (maker Coinkite). 6) For backups: use air-gapped Ledger or Trezor as secondary hardware wallet.
YTD crypto hacks: $1.2B+ across 276 incidents. Early 2026 was dominated by smart contract exploits ($200M+ in DeFi bridges). August 2026 marked a pivot: hardware wallet flaws are now the new attack surface. Expect audits of Ledger, Trezor, and Keystone firmware in coming weeks.
Hardware wallets, exchanges, custodians—each has trade-offs. True security requires (1) diversified storage (hardware + custodian split), (2) regular updates, (3) multi-sig if holding >$1M. The Coldcard hack shows even 'best-in-class' solutions have blind spots. Stay vigilant.
Read More →