Skip to content
LIVE MARKETS
Loading market data …………………………
🌤
BREAKING
Crypto firms frontier AI access: why only a few have it Coldcard Bitcoin theft tops $100M in three waves Nigeria crypto tax collection rules explained How the Fed could help defend Japan’s yen
Crypto and Forex

Coldcard Bitcoin theft tops $100M in three waves

Over $100M in Bitcoin has been stolen from Coldcard hardware wallets across three confirmed attack waves, with investigators tracking a potential fourth.

Photo: Gage Skidmore via Openverse (BY-SA)

Key Takeaways

  • Coldcard bitcoin theft has exceeded $100M across confirmed attacks, with most stolen funds still untouched
  • Investigators are examining a suspected fourth wave that could push losses toward $130M
  • The prolonged security incident highlights risks even with hardware wallets, which are considered safer than exchanges

More than $100 million in Bitcoin has vanished from Coldcard hardware wallets across three separate, confirmed attack waves, according to analysis by Galaxy Research published in early August 2026.

The scale of the theft is striking not just for the dollar figure, but for what happened afterwards: roughly 90% of the stolen Bitcoin remains sitting untouched in blockchain addresses, suggesting the attackers may still be deciding what to do with their haul.

Galaxy Research investigators are now scrutinising a suspected fourth attack wave that has not yet been officially confirmed but could push total losses toward $130 million if verified.

Why this happened and what it reveals about hardware wallet security

Coldcard is a physical device that stores private keys (the cryptographic passwords that unlock your Bitcoin) offline, away from internet-connected computers and phone apps. This “air-gapped” approach has long been marketed as one of the safest ways to own crypto because there is no connection for hackers to exploit remotely.

Yet the coldcard bitcoin theft scandal demonstrates that hardware wallets are not invulnerable. The exact attack vector has not been fully disclosed in the limited information available, but such breaches typically stem from either a vulnerability in the device firmware (the embedded software running on it), a flaw in how users set them up, or a supply-chain compromise where wallets are intercepted and tampered with before reaching customers.

The fact that attackers have struck in waves suggests they are either testing a repeatable exploit, targeting specific user groups, or exploiting a known vulnerability that Coldcard has not yet patched across all affected devices.

What makes the coldcard bitcoin theft especially concerning is the psychological gap it exposes: hardware wallets enjoy a halo of invincibility among crypto holders. Most people who buy them do so precisely because they believe they are immune to hacks. This incident shatters that assumption.

What happens next and what this means for the broader ecosystem

The dormancy of the stolen funds is oddly revealing. When cybercriminals successfully steal cryptocurrency, they typically move it quickly through mixing services or decentralised exchanges to obscure its origin. The fact that 90% remains stationary suggests either the attackers are waiting for regulatory heat to cool, planning a coordinated exit, or are simply holding the Bitcoin as a long-term store of value.

For Coldcard itself, the damage extends beyond the financial loss. Users will now question whether their devices are secure, creating a trust crisis. Competing hardware wallet manufacturers like Ledger and Trezor will face increased scrutiny as well, and the entire category risks losing credibility if firmware vulnerabilities are found to be widespread.

Could this happen to other hardware wallets?

Possibly, yes. If the coldcard bitcoin theft stems from a firmware bug or a supply-chain weakness rather than user error, the same vulnerability could exist in other devices. Investigators examining the fourth wave will be crucial in determining whether this is a Coldcard-specific problem or a systemic issue affecting the industry.

What this means for you

If you own cryptocurrency, this incident raises real questions about where to keep it and how to secure it properly.

  • Check your device: if you own a Coldcard, update the firmware immediately and verify that your wallet has not been compromised. Most hardware wallets allow you to check transaction history on the device itself.
  • Diversify storage: rather than trusting a single device or method, consider splitting your holdings across multiple wallets (a cold wallet for long-term storage, perhaps a smaller amount on an exchange or mobile app for spending), which reduces the damage if one is compromised.
  • Stay informed on patches: hardware wallet security is only as strong as the most recent firmware update. Enable notifications from your manufacturer or follow their security channels closely.

Thewealthora has published in-depth guides on how to choose a hardware wallet, how to secure your crypto holdings, and how to recover from a security breach if it happens to you.

Go deeper on Thewealthora

Originally reported by Cointelegraph. Facts verified; analysis and wording are Thewealthora’s own.

Was this helpful?

Arpit Soni

The Thewealthora desk covers markets, money and personal finance, with zero jargon and every claim sourced.

Leave a Reply

Your email address will not be published. Required fields are marked *