How Hackers Drained $70M From Bitcoin Cold Wallets Remotely
Attackers stole $70 million from bitcoin cold wallets without ever physically accessing the devices, exposing a critical gap in hardware security assumptions.
Cybercriminals siphoned approximately $70 million worth of bitcoin from cold wallets — storage devices long considered the gold standard of cryptocurrency security — without ever making physical contact with the hardware, according to a CoinDesk report. The attack has rattled the crypto security community, which has historically treated offline, air-gapped wallets as near-impenetrable safeguards against remote theft.
Cold wallets are designed to keep private keys disconnected from the internet, theoretically eliminating the attack surface available to remote hackers. The fact that this breach succeeded without touching the physical devices suggests that the vulnerability lay not in the hardware itself but in the surrounding software ecosystem — including wallet management interfaces, signing processes, or supply-chain components that interact with the cold storage at critical moments.
Read more Jim Cramer Cheers Apple's AI Push as Stock Reclaims Top Market Cap →
The incident underscores a widening recognition among security researchers that "cold" storage is only as secure as the processes wrapped around it. Even briefly connecting a cold wallet to a computer to authorize a transaction can expose users to malicious software capable of intercepting signing data, substituting recipient addresses, or capturing seed phrases before they reach the secure chip.
For institutional and retail bitcoin holders alike, the attack raises urgent questions about operational security practices — from how firmware is verified, to whether signing ceremonies are conducted on hardened machines, to whether seed-phrase backups are themselves stored securely offline. Experts generally advise using dedicated, never-networked computers for any interaction with cold wallets, and verifying transaction details on the wallet's own screen rather than trusting what a connected host device displays.
The $70 million loss ranks among the more significant cold-wallet compromises on record and is likely to accelerate scrutiny of the entire hardware-wallet supply chain. Continue reading at CoinDesk.