markets

How Hackers Drained $70M From Bitcoin Cold Wallets Remotely

Summarized from CoinDesk

Attackers stole $70 million from bitcoin cold wallets without ever physically accessing the devices, exposing a critical gap in hardware security assumptions.

Cybercriminals siphoned approximately $70 million worth of bitcoin from cold wallets — storage devices long considered the gold standard of cryptocurrency security — without ever making physical contact with the hardware, according to a CoinDesk report. The attack has rattled the crypto security community, which has historically treated offline, air-gapped wallets as near-impenetrable safeguards against remote theft.

Cold wallets are designed to keep private keys disconnected from the internet, theoretically eliminating the attack surface available to remote hackers. The fact that this breach succeeded without touching the physical devices suggests that the vulnerability lay not in the hardware itself but in the surrounding software ecosystem — including wallet management interfaces, signing processes, or supply-chain components that interact with the cold storage at critical moments.

Read more Jim Cramer Cheers Apple's AI Push as Stock Reclaims Top Market Cap →

The incident underscores a widening recognition among security researchers that "cold" storage is only as secure as the processes wrapped around it. Even briefly connecting a cold wallet to a computer to authorize a transaction can expose users to malicious software capable of intercepting signing data, substituting recipient addresses, or capturing seed phrases before they reach the secure chip.

For institutional and retail bitcoin holders alike, the attack raises urgent questions about operational security practices — from how firmware is verified, to whether signing ceremonies are conducted on hardened machines, to whether seed-phrase backups are themselves stored securely offline. Experts generally advise using dedicated, never-networked computers for any interaction with cold wallets, and verifying transaction details on the wallet's own screen rather than trusting what a connected host device displays.

The $70 million loss ranks among the more significant cold-wallet compromises on record and is likely to accelerate scrutiny of the entire hardware-wallet supply chain. Continue reading at CoinDesk.

Frequently Asked Questions

Q.How did hackers steal from cold wallets without physically accessing them?

The attack exploited vulnerabilities in the software ecosystem surrounding the cold wallets — such as signing interfaces or connected host devices — rather than the hardware itself, allowing thieves to intercept or manipulate transactions remotely.

Q.Are cold wallets still safe for storing bitcoin?

Cold wallets remain one of the most secure storage options, but this incident shows they are only as safe as the operational practices around them, including how and when they are connected to other devices.

Q.How much bitcoin was stolen in the cold wallet attack?

Approximately $70 million worth of bitcoin was drained from cold wallets in the attack, making it one of the more significant hardware-wallet breaches on record.

More in markets →