Bitcoin Magazine reported on August 7 that a hack connected to Coldcard hardware wallets has resulted in reported losses exceeding $111 million. The outlet said victims have come forward describing a median individual loss of 1 BTC, a figure that suggests the incident touched a wide range of holders rather than concentrating losses among a few large accounts.
Coldcard is a hardware wallet used by bitcoin holders who want to keep private keys offline, away from internet-connected devices. Hardware wallets are widely considered one of the safer methods for storing cryptocurrency, since they are designed to prevent remote attackers from accessing a user’s keys. Reports of a hack affecting this category of device raise questions about how the breach occurred and what part of the security chain may have failed.
The scale of the reported theft, more than $111 million, would place this among the larger bitcoin-related loss events reported this year. The median loss of 1 BTC indicates that many affected users held modest amounts rather than institutional-sized holdings. That detail matters because it suggests the incident may have affected retail users broadly, rather than targeting a small number of high-value wallets.
Bitcoin Magazine’s report did not, based on available details, specify the exact mechanism behind the losses, such as whether the issue stemmed from a supply-chain compromise, a software vulnerability, phishing tied to the brand, or a separate attack vector. Hardware wallet incidents in the past have involved a range of causes, including counterfeit devices, tampered seed phrase backups, and social engineering schemes that trick users into revealing recovery phrases.
Users of hardware wallets are generally advised to purchase devices directly from manufacturers or authorized resellers, verify device authenticity upon setup, and never share seed phrases with any third party, including support staff. Given the reported scale of losses in this case, security researchers and the wallet’s manufacturer may face pressure to clarify what happened and whether affected users have any recourse.
As with many emerging security incidents in crypto, early reports can evolve as more victims come forward or as investigators publish findings. Readers should treat the $111 million figure and the median loss estimate as preliminary pending further detail from Coldcard or independent security researchers.
Sources disagree on this story
This article was published before the reports below were compared. The reporting above stands; what follows is where the published accounts do not agree.
Bitcoin Magazine and AMBCrypto agree on the scale of the Coldcard theft but give different accounts of which devices were vulnerable and whether the technical cause has been confirmed.
What all sources agree on
- Galaxy Research found that at least $111 million (about 1,719 BTC) has been confirmed stolen, with total losses potentially exceeding $130 million.
- Over 250 victims have reported losses.
- Stolen funds came overwhelmingly from long-dormant wallets.
- Individual victims reported a median loss of roughly 1 BTC.
- The vulnerability was tied to firmware released after March 2021.
Where the reports disagree
1Which Coldcard hardware models were affected
a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases.
Galaxy Research said that not every Coldcard wallet faced exposure. However, Mk3, Mk4, Mk5, and Q models appeared vulnerable. Those models ran firmware released after 17th March 2021.
What would settle it: Coinkite's official security advisory or firmware changelog identifying the affected models.
2Whether the technical root cause of the flaw has been confirmed
a firmware bug in Coldcard Mk3 devices — starting with version 4.0.1 in March 2021 — caused seed generation to fall back to a weak software Pseudorandom Number Generator instead of the hardware true random number generator, allowing hackers to essentially guess investor seedphrases.
The flaw may have affected wallet-seed security or generation.
What would settle it: Coinkite's official statement detailing the confirmed technical root cause of the vulnerability.
What to make of it
Treat the $111 million loss figure and the median 1 BTC individual loss as established across sources; do not treat the list of affected Coldcard models or the exact technical cause as settled until Coinkite issues its own detailed advisory.
Market Impact
A hack of this reported size could weigh on sentiment toward hardware wallets generally, even though the broader category remains a standard recommendation for securing bitcoin holdings. If confirmed, losses topping $111 million would represent a meaningful dent in retail confidence, particularly among users who rely on Coldcard specifically.
Any sustained reputational fallout could push some holders toward alternative custody solutions, including multisignature setups or other hardware wallet brands. The incident also arrives amid ongoing scrutiny of self-custody security practices, which could prompt renewed discussion around wallet verification processes and supply-chain integrity checks across the hardware wallet industry.
The full scope and cause of the reported Coldcard-related losses remain to be clarified, and readers should watch for further statements from the manufacturer or independent security researchers.
Frequently Asked Questions
What is Coldcard?
Coldcard is a hardware wallet designed to store bitcoin private keys offline, away from internet-connected devices, as a way to reduce exposure to remote hacking attempts.
How much was reportedly stolen in this incident?
Bitcoin Magazine reported total losses exceeding $111 million, based on accounts from affected victims.
What was the median loss per victim?
According to the report, the median individual loss was 1 BTC, suggesting a broad range of affected holders rather than a few large losses.
Has Coldcard confirmed the cause of the hack?
The reporting reviewed did not specify a confirmed cause, and further detail from Coldcard or independent security researchers would be needed to clarify how the losses occurred.
What should hardware wallet users do to protect themselves?
General security guidance includes buying devices only from manufacturers or authorized sellers, verifying device authenticity, and never sharing seed phrases with anyone.