A reported security flaw in the Coldcard hardware wallet is linked to a large Bitcoin theft and an unprecedented wave of coin migration.
A reported vulnerability in the Coldcard hardware wallet has been tied to a major Bitcoin theft, according to two separate reports published on August 12, 2026. CoinTurk News put the stolen amount at roughly $130 million, while crypto.news, citing a source referred to as Gray, estimated the exposure at approximately $116 million. Both figures point to a substantial breach involving a device marketed as a secure, offline method for storing Bitcoin private keys.
Coldcard is a hardware wallet designed for self-custody, allowing users to hold their own private keys instead of relying on exchanges or third-party custodians. Devices in this category are typically viewed as among the safer options in the crypto ecosystem, since they keep keys isolated from internet-connected systems. A flaw affecting such a device raises questions about the broader assumptions underpinning self-custody security.
Alongside the theft reports, both sources noted a record migration of about 233,000 BTC. The scale of that movement suggests a large-scale reaction among holders, though the exact motivations behind each transaction were not detailed. Some of the movement may reflect precautionary transfers by users seeking to move funds to new wallets or storage methods following news of the exploit.
The discrepancy between the two theft estimates, $130 million versus $116 million, has not been resolved. Differences of this kind are common in the early stages of security incident reporting, when data sources and calculation methods can vary. Readers should treat both figures as reported estimates rather than confirmed totals until further clarification emerges.
Self-custody has long been promoted within the Bitcoin community as a defense against exchange failures, hacks, and counterparty risk. The core principle rests on the idea that users who control their own keys are not exposed to the failures of centralized platforms. An exploit affecting a widely used hardware wallet challenges that narrative, at least in the context of device-level vulnerabilities.
Hardware wallet manufacturers generally respond to reported flaws with firmware updates, security advisories, or public statements addressing the scope of any vulnerability. Neither report specified whether Coldcard’s maker had issued an official response at the time of publication. Users of the device may need to wait for further guidance before determining appropriate next steps.
The timing of the reported theft alongside the large BTC migration suggests the two events are connected, though the precise mechanics of how the exploit was used to move funds were not detailed in either report. Blockchain analysts and security researchers often examine on-chain data in the aftermath of such incidents to trace stolen funds and identify affected wallet clusters.
This article was published before the reports below were compared. The reporting above stands; what follows is where the published accounts do not agree.
Four outlets agree a Coldcard firmware flaw exposed Bitcoin seeds, but they report different totals for how much was stolen.
Attackers drained approximately 2,100 Bitcoin across multiple attack waves.
Attackers have reportedly drained about 1,816 BTC worth $116 million from more than 5,200 addresses.
attackers drained approximately 1,816 BTC, worth about $116 million, from more than 5,200 addresses in four suspected waves that began on July 30.
What would settle it: A consolidated on-chain forensic accounting from Coinkite or a blockchain intelligence firm (e.g., TRM Labs, Galaxy Research) reconciling all affected addresses.
A major security breach targeting Coldcard hardware wallets has resulted in losses approaching $130 million
The Coldcard seed-generation failure has exposed about $116 million in Bitcoin to theft
Estimated exposure has been placed in the range of nine figures, with potential losses from the Coldcard hack nearing $114 million, a figure separate from the total volume of Bitcoin relocated in response.
A flaw in Coldcard hardware wallets exposed about $116 million (1,816 BTC) across more than 5,200 addresses, according to TRM Labs.
What would settle it: TRM Labs’ final loss report or Coinkite’s own confirmed victim/address tally, once investigators finish tracing all affected addresses.
Treat the underlying cause — a firmware entropy flaw affecting Coldcard versions 4.0.1–4.1.9 since March 2021 — as established, but do not cite a single dollar or BTC loss figure as final since reports range from 1,596–2,100 BTC and $114M–$130M for what may still be an evolving tally.
A theft of this scale, even at the lower $116 million estimate, is large enough to draw attention across the Bitcoin security community and among hardware wallet users generally. Reports of vulnerabilities in self-custody devices can prompt short-term caution among holders, sometimes visible in on-chain wallet migration patterns like the 233,000 BTC movement described here.
Beyond the immediate financial loss, incidents involving hardware wallets can affect confidence in self-custody solutions more broadly. Renewed scrutiny of wallet security practices, firmware auditing, and supply chain integrity often follows disclosures of this kind, particularly if the exploit is confirmed and its technical details become public.
The full scope of the Coldcard-linked theft, including the exact loss figure and the cause of the exploit, remains subject to further reporting and verification. The scale of the accompanying Bitcoin migration underscores how quickly holders can react to security concerns involving self-custody tools.
Coldcard is a hardware wallet designed to let Bitcoin holders store their private keys offline for self-custody, rather than relying on exchanges or third-party custodians.
Estimates differ between sources. CoinTurk News reported approximately $130 million in losses, while crypto.news cited a figure of about $116 million, attributed to a source referred to as Gray.
Reports describe a record migration of about 233,000 BTC coinciding with the exploit disclosure, which may reflect holders moving funds as a precaution, though the exact reasons for each transaction were not specified.
Neither source referenced an official statement from the device’s manufacturer at the time of publication, so any formal response remained unconfirmed.
Hardware wallets are generally considered a secure self-custody option, but any reported vulnerability, once confirmed, can prompt reassessment of specific devices or firmware versions rather than the category as a whole.
Original source: AltcoinGordon