Coldcard Hack Drains at Least 1,432 Bitcoin, Investigators Say
Coldcard, a Bitcoin-only hardware wallet made by Canada’s Coinkite, is designed to let users hold their own private keys rather than rely on an exchange. The breach matters because self-custody removes the central account records investigators normally use to identify victims and total losses. Analysts must instead combine victim reports with transaction timing, address clustering and fund-flow patterns, making attribution — and any estimate of the theft — inherently provisional.
The attack surfaced on July 30, 2026, when Galaxy Research traced about 1,082 bitcoin leaving 1,196 wallet addresses in a 41-minute sweep. By Aug. 11, CryptoQuant estimated confirmed losses at no less than 1,432 bitcoin. Galaxy and TRM Labs have put the likely scale higher, though the precise total remains disputed because some addresses are linked to Coldcard only through behavioral signatures rather than a centralized customer list or direct reports from victims.
All Coverage
1 original reportsThe Backstory
The history behind this eventColdcard Fallout Moves 210,000 Bitcoin From Long-Held Wallets
The Coldcard security incident has put renewed attention on the risks surrounding hardware-wallet custody, particularly for long-term bitcoin holders whose control of assets depends on secure devices and private keys. Large transfers from dormant or older addresses can signal selling pressure, but they may also reflect wallet upgrades, security precautions or a shift toward third-party custody rather than a change in market conviction.
Glassnode data showed that about 210,000 bitcoin moved out of long-held wallets during the latest week covered by the report. The onchain flows indicate that users primarily transferred the assets to newly created wallets or regulated custody services following the Coldcard incident. That pattern points to a redistribution of custody arrangements, rather than the type of exchange-bound movement typically associated with broad market selling.
Coldcard Mk3 Flaw Spurs Probe of $38 Million Bitcoin Transfer
Coldcard Mk3, made by Coinkite, is a hardware wallet designed to keep bitcoin signing keys offline. Coinkite warned that seed phrases generated by certain firmware could leave funds exposed and told customers to migrate assets to newly secured wallets. The issue matters beyond retail users because hardware wallets underpin self-custody and form part of institutional storage arrangements. A failure in seed generation can defeat the physical isolation that makes such devices trusted, intensifying scrutiny of cryptocurrency custody controls.
As of Aug. 7, 2026, security researchers were tracing an anomalous transfer of 594.48 bitcoin, worth about $38 million. Subsequent reports said 4,585 wallets had been drained and put broader losses near $130 million, though estimates varied; Galaxy said at least 15 attackers exploited the weakness. Hackers also moved 64 bitcoin and 200 ether to cryptocurrency mixers. Coinkite urged Mk3 users to transfer funds while exploitation continued. Investigators have not established that the original 594.48-bitcoin transfer was directly caused by the Mk3 flaw.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.