Coldcard Bitcoin theft tops $100M in three waves
Over $100M in Bitcoin has been stolen from Coldcard hardware wallets across three confirmed attack waves, with investigators tracking a potential fourth.

Key Takeaways
- Coldcard bitcoin theft has exceeded $100M across confirmed attacks, with most stolen funds still untouched
- Investigators are examining a suspected fourth wave that could push losses toward $130M
- The prolonged security incident highlights risks even with hardware wallets, which are considered safer than exchanges
More than $100 million in Bitcoin has vanished from Coldcard hardware wallets across three separate, confirmed attack waves, according to analysis by Galaxy Research published in early August 2026.
The scale of the theft is striking not just for the dollar figure, but for what happened afterwards: roughly 90% of the stolen Bitcoin remains sitting untouched in blockchain addresses, suggesting the attackers may still be deciding what to do with their haul.
Galaxy Research investigators are now scrutinising a suspected fourth attack wave that has not yet been officially confirmed but could push total losses toward $130 million if verified.
Why this happened and what it reveals about hardware wallet security
Coldcard is a physical device that stores private keys (the cryptographic passwords that unlock your Bitcoin) offline, away from internet-connected computers and phone apps. This “air-gapped” approach has long been marketed as one of the safest ways to own crypto because there is no connection for hackers to exploit remotely.
Yet the coldcard bitcoin theft scandal demonstrates that hardware wallets are not invulnerable. The exact attack vector has not been fully disclosed in the limited information available, but such breaches typically stem from either a vulnerability in the device firmware (the embedded software running on it), a flaw in how users set them up, or a supply-chain compromise where wallets are intercepted and tampered with before reaching customers.
The fact that attackers have struck in waves suggests they are either testing a repeatable exploit, targeting specific user groups, or exploiting a known vulnerability that Coldcard has not yet patched across all affected devices.
What makes the coldcard bitcoin theft especially concerning is the psychological gap it exposes: hardware wallets enjoy a halo of invincibility among crypto holders. Most people who buy them do so precisely because they believe they are immune to hacks. This incident shatters that assumption.
What happens next and what this means for the broader ecosystem
The dormancy of the stolen funds is oddly revealing. When cybercriminals successfully steal cryptocurrency, they typically move it quickly through mixing services or decentralised exchanges to obscure its origin. The fact that 90% remains stationary suggests either the attackers are waiting for regulatory heat to cool, planning a coordinated exit, or are simply holding the Bitcoin as a long-term store of value.
For Coldcard itself, the damage extends beyond the financial loss. Users will now question whether their devices are secure, creating a trust crisis. Competing hardware wallet manufacturers like Ledger and Trezor will face increased scrutiny as well, and the entire category risks losing credibility if firmware vulnerabilities are found to be widespread.
Could this happen to other hardware wallets?
Possibly, yes. If the coldcard bitcoin theft stems from a firmware bug or a supply-chain weakness rather than user error, the same vulnerability could exist in other devices. Investigators examining the fourth wave will be crucial in determining whether this is a Coldcard-specific problem or a systemic issue affecting the industry.
What this means for you
If you own cryptocurrency, this incident raises real questions about where to keep it and how to secure it properly.
- Check your device: if you own a Coldcard, update the firmware immediately and verify that your wallet has not been compromised. Most hardware wallets allow you to check transaction history on the device itself.
- Diversify storage: rather than trusting a single device or method, consider splitting your holdings across multiple wallets (a cold wallet for long-term storage, perhaps a smaller amount on an exchange or mobile app for spending), which reduces the damage if one is compromised.
- Stay informed on patches: hardware wallet security is only as strong as the most recent firmware update. Enable notifications from your manufacturer or follow their security channels closely.
Thewealthora has published in-depth guides on how to choose a hardware wallet, how to secure your crypto holdings, and how to recover from a security breach if it happens to you.
Go deeper on Thewealthora
- Bitcoin cold storage exploit: $90m stolen
- Crypto home invasions surge to 20 cases in first half of 2026
- New malware threatens crypto investors through fake apps
Originally reported by Cointelegraph. Facts verified; analysis and wording are Thewealthora’s own.