Bitcoin has been drained from Coldcard hardware wallets in an exploit reported in early August 2026, one of the largest thefts of self-custodied bitcoin in recent memory. Coldcard is a hardware, or cold storage, wallet made by Canada-based Coinkite Inc., a device category widely recommended precisely because it keeps private keys offline and away from internet-connected attackers.
The thefts stem from a software flaw, not from owners exposing seed phrases or falling for phishing in the traditional sense. Affected owners experienced four separate waves of thefts, suggesting the exploit was used repeatedly over time rather than in a single coordinated sweep.
Blockchain analytics firms have produced different tallies of the damage, and the two counts do not match. TRM Labs counted more than $116 million taken from over 5,200 addresses. Galaxy Research confirmed more than $100 million across roughly 7,300 addresses, and suspects the real total is closer to $130 million across more than 7,700 addresses. Because the two firms’ counts differ, the total is best understood as a moving estimate that has continued to change as analysis proceeds, not a final, agreed-upon figure.
What it means
The core lesson is an uncomfortable one for the self-custody community: a hardware wallet is only as secure as the software running on it. Cold storage is designed to defend against remote attackers by keeping keys offline, but a flaw in the device’s own software can undercut that protection regardless of how carefully an owner otherwise handles their seed phrase. Owners who bought a Coldcard specifically to move bitcoin out of exchange custody and into self-custody now have to reckon with a scenario where the self-custody device itself was the point of failure. That does not make custodial exchange accounts inherently safer, since those carry their own well-documented risks, but it does complicate the simple story that moving funds off an exchange automatically removes exposure to theft.
The gap between TRM Labs’ and Galaxy Research’s figures, both firms that specialize in tracing stolen crypto, is itself informative. It shows how difficult it is to get a precise number quickly after a rolling, multi-wave exploit, since new affected addresses can keep surfacing as investigators expand their search. Readers should treat any single total cited in the days after an incident like this as provisional rather than final.
For owners of hardware wallets generally, the episode is a reminder to keep device firmware current and to watch for official guidance from the manufacturer, since the specific defense against a software-level flaw is a software-level fix, not just good key-handling habits. Our guide to wallet security, seed phrases, and hardware backups covers the broader practices that reduce exposure to this kind of risk, and our comparison of custodial versus self-custody wallets lays out the tradeoffs between the two approaches.
As with any actively investigated hack, figures here can and likely will keep moving. Readers should watch for updated numbers from TRM Labs, Galaxy Research, and Coinkite as the investigation continues, and treat any total reported in the immediate aftermath, including the ones in this article, as an estimate rather than a settled figure. Coinkite’s device is a widely used option in the self-custody hardware wallet category, which is part of why an exploit against it, rather than against a single exchange, was able to reach so many separate owners across four distinct waves of theft.
Sources
- Fortune — Bitcoin owners rocked by $116 million hack: What we know about the Coldcard exploit
- Bloomberg — Coldcard Bitcoin Wallets Compromised as Hackers Exploit Software Flaw
Nothing here is investment, legal, or tax advice. Crypto is volatile and high-risk; regulatory and tax treatment varies by state and changes over time. Consult a licensed professional before making financial decisions.
Last updated August 13, 2026
DeFi and on-chain reporter at Crypto News US, covering lending markets, decentralised exchanges, stablecoins and the spread of activity across layer-2 networks.
