Bad actors fleeced investors of an estimated $130 million by exploiting a software flaw in an offline hardware wallet called Coldcard.