A reported $70 million exploit in Coldcard hardware wallets reveals vulnerabilities in key generation, undermining trust in air-gapped storage solutions.
A firmware vulnerability in Coldcard hardware wallets has exposed a critical flaw in self-custody security, with reports linking it to a $70 million exploit. The bug allegedly compromised randomness during wallet creation, allowing attackers to reconstruct private keys without physical access to devices.
The issue underscores that secure self-custody depends on both offline storage and robust key generation. Even air-gapped wallets are vulnerable if initial entropy is insufficient, and firmware updates cannot retroactively fix compromised recovery phrases.
Investors are advised to review seed creation processes and diversify custody methods to mitigate risks. The incident highlights broader concerns about hardware wallet reliability in high-value crypto storage.