started · updated
Coldcard exploit victims pursue legal action against Coinkite
Victims of a major security exploit involving Coinkite’s Coldcard hardware wallets are exploring legal action and asset recovery. The exploit, which targeted a five-year-old firmware vulnerability, resulted in the loss of approximately 1,816 BTC (valued at roughly $116 million) across more than 5,200 addresses.
Toronto-based law firm WeirFoulds LLP is conducting preliminary consultations to represent victims in seeking damages. Legal experts are examining potential product liability claims against Coinkite, arguing that the manufacturer may have failed to meet necessary security standards, testing, or disclosure obligations. This case could set a precedent regarding the responsibility of hardware wallet manufacturers when firmware flaws compromise self-custody security.
In terms of recovery, blockchain analysis has confirmed the movement of approximately 52.37 BTC linked to the exploit. A white-hat hacker moved these funds to the Crypto Recovery Trust, as evidenced by transaction records in block 967,948. This amount represents roughly 2.8% of the total funds tracked by Galaxy Research as being part of the Coldcard exploit.
Entities
Coinkite · Coldcard · Crypto Recovery Trust · Galaxy Research · WeirFoulds LLP