Canadian hardware wallet maker Coinkite has destroyed its remaining inventory of Coldcard devices after a firmware vulnerability was exploited to steal more than $88 million in bitcoin from customers. The company confirmed last week that a flaw first discovered in March 2021 is now being actively used to breach wallets that were meant to keep funds safely offline.

According to cybersecurity firm Galaxy Research, the attackers have stolen at least 1,367.05 BTC, worth roughly $88.6 million, drained from 4,585 addresses. Blockchain analysis firm Chainalysis said the campaign appears highly targeted, with attackers hitting high-value wallets first, including one victim who lost $1.8 million. The firm noted the cumulative theft reached roughly $30 million within the first 10 minutes, suggesting the attacker had studied the population of victim wallets in advance. Two of the largest victims lost a combined $4 million, and numerous other bitcoin holders have come forward on social media describing losses.

Response and mitigation

In a statement, Coldcard urged affected customers not to dispose of their devices, saying they may be needed if funds are recovered, and said its legal team would coordinate with law enforcement across multiple jurisdictions to help identify those responsible.

The company said it halted shipments once the vulnerability was confirmed and destroyed all remaining inventory manufactured with the vulnerable firmware. Coinkite explained that Coldcard devices have high-security system locks that cannot be upgraded until a user initializes the unit, meaning it could not safely ship existing stock and risk users missing the firmware upgrade. A patched firmware version has now been released that the company says prevents the issue from recurring.

Coinkite did not respond to questions about whether it plans to compensate affected customers. The FBI declined to comment on whether it is investigating the campaign.

AI-assisted bug hunting cited as a factor

A senior Coinkite official said the incident was driven in part by attackers using AI-assisted code review tools, which allowed them to find latent bugs faster than even experienced security researchers. The comment highlights growing concern that AI tooling is accelerating the discovery of exploitable flaws in previously reviewed codebases, including firmware that had already undergone scrutiny for years before the flaw was weaponized.