Coldcard exploit drains $120 million and congests Bitcoin’s mempool

A reported exploit linked to Coldcard, an offline Bitcoin hardware wallet, drained $120 million and triggered a rapid surge of transfers that overwhelmed Bitcoin’s mempool, the queue of unconfirmed transactions. The mempool rose above 200 megabytes across two block intervals, while fees increased sharply and some medium-priority transactions reportedly required several dollars in sats per vbyte for inclusion in the next block. CoinJoin rounds, over-the-counter settlement batches and ordinary wallet transfers were caught in the congestion during the early Asian hours. The incident’s exact attack vector remains unconfirmed, but the loss is prompting renewed scrutiny of firmware integrity, reproducible builds, offline verification, multisignature custody and reliance on companion desktop applications. It may also intensify regulatory pressure on self-custody and accelerate security audits and institutional-grade custody offerings.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.