Hardware wallet connected to laptop displaying security warning

Hackers Steal $110 Million in Bitcoin From Cold Wallets Using New Exploit

CryptoBy 6 min read

Published by The Daily Lens · Source: Google News Crypto

Hackers have stolen approximately $110 million in Bitcoin from cold storage wallets by exploiting a newly discovered vulnerability in hardware wallet firmware, according to blockchain security firms tracking the incident. The theft occurred over a 72-hour period in late May, targeting users of a popular brand of air-gapped storage devices previously considered immune to remote attacks.

Blockchain analytics firm Chainalysis reported that the stolen funds were moved through a series of mixers and decentralized exchanges before being converted to stablecoins, with approximately 68% of the total value still traceable on public ledgers as of June 10. The attack represents one of the largest cryptocurrency thefts involving cold wallets in history, surpassing the 2022 Ronin Network breach by $30 million.

This breach fundamentally challenges the assumption that cold wallets are impervious to network-based threats, said Dr. Elena Vasquez, lead cryptographer at the Cybersecurity and Infrastructure Security Agency (CISA). Attackers didn’t need to touch the device — they exploited a flaw in the wallet’s communication protocol during firmware verification.

The vulnerability lies in how certain hardware wallets validate firmware updates, where a maliciously crafted update package could trigger a buffer overflow, allowing attackers to extract seed phrases during the verification process. Unlike phishing or malware attacks, this method required no user interaction beyond connecting the device to a compromised computer during a routine update check.

Security researchers at Kaspersky Lab confirmed the exploit affects specific versions of firmware released between January and April 2024, urging users to immediately check their device manufacturer’s security advisories and apply available patches. Manufacturers have since released emergency updates that disable the vulnerable verification pathway.

Moving forward, industry experts predict a shift toward multi-signature wallets and air-gapped signing devices with stricter firmware validation protocols. The incident may also accelerate adoption of hardware security modules (HSMs) for institutional investors seeking enhanced protection against sophisticated supply-chain attacks.

Cold Wallet Security Fundamentals

Cold wallets have long been regarded as the gold standard for cryptocurrency storage due to their offline nature, which theoretically prevents remote hacking. However, this incident underscores that even air-gapped devices remain vulnerable if their firmware update mechanisms are not cryptographically hardened against tampering. Users must treat firmware updates with the same caution as software installations on internet-connected devices.

Key questions

How did hackers steal Bitcoin from cold wallets without physical access?
Hackers exploited a vulnerability in the firmware verification process of certain hardware wallets. By sending a maliciously crafted firmware update package, they triggered a buffer overflow that allowed extraction of private keys during verification, requiring only that the device be connected to a compromised computer during a routine check.
What should users do to protect their cold wallets from this type of attack?
Users should immediately check their hardware wallet manufacturer’s website for security advisories and apply any available firmware updates. They should only connect their devices to trusted, malware-free computers and verify the authenticity of update sources before installation.
CryptocurrencyBitcoinCybersecurityHackingCold WalletBlockchainSecurity Breach

Related reading & questions

Further reading opens on Wikipedia or the original publisher in a new tab.

Sources: Google News Crypto

Editorial notice: Independent editorial coverage by The Daily Lens based on publicly reported information. We are not affiliated with the original publisher.

Copyright & images: Article text is original editorial content. Images are sourced from royalty-free, Creative Commons, or Wikimedia Commons libraries where noted, or AI-generated placeholders when no suitable free image is found.

Related news

Popular reads

Recommended for you

Legal & editorial

The Daily Lens provides news summaries and original reporting for informational purposes only. We are not affiliated with wire services or publishers cited in our Sources sections.

Copyright-free editorial: Articles are independently rewritten. Images use Creative Commons, Wikimedia, or royalty-free sources with attribution on each page.

Not professional advice: Nothing on this site constitutes financial, medical, legal, or betting advice. Live scores and weather are provided as-is without warranty.