Coldcard Firmware Vulnerability Leads to $88 M Bitcoin Theft, Manufacturer Destroys Affected Inventory
What Happened – A firmware flaw in Coldcard hardware wallets, first disclosed in March 2021, was weaponised in a campaign that stole roughly $88 million (1,367 BTC) from 4,585 addresses. Coinkite, the maker of Coldcard, halted shipments and destroyed all remaining units that shipped with the vulnerable firmware, while releasing a patched version.
Why It Matters for Compliance & Audit Readiness
- The incident underscores the need for SOC 2‑aligned Change Management (CC6.1) and Software Development (CC7.1) controls that require documented firmware updates, testing, and evidence of remediation.
- Continuous evidence collection and control mapping demonstrate due‑diligence to auditors and regulators when a product flaw leads to asset loss.
- A robust Control Mapping capability provides the audit trail needed to prove that vulnerable code was identified, patched, and that inventory was safely handled.
Who Is Affected – Financial‑services firms, crypto custodians, and any organization that relies on hardware wallets for offline asset storage.
Recommended Actions
- Map the firmware development and release process to SOC 2 change‑management controls; capture build hashes, test results, and approval records as audit evidence.
- Implement continuous monitoring of firmware versions in the field and enforce mandatory updates for all deployed devices.
- Conduct a third‑party risk review of the hardware‑wallet supplier, documenting the vulnerability and remediation steps in your vendor‑risk register.
Source: The Record
Technical Notes – The exploited flaw was a previously disclosed firmware vulnerability (no public CVE) that allowed attackers to extract private keys from the device. Attack vector: vulnerability exploit; impact: confirmed exposure of private keys and theft of cryptocurrency assets. Source: The Record