Skip to content
Active Currencies: 18,114
Market Cap: $2.268T
Bitcoin Dominance: 56.45%
24h Market Cap Change: $1.41

Coldcard exploit crosses $100M with 1,596 Bitcoin stolen: Wave 4 can push losses to $130M

The Coldcard exploit has become a major hardware wallet security incident, renewing scrutiny of self-custody practices.

Coldcard exploit crosses $100M with 1,596 BTC stolen: Wave 4 can push losses to $130M

What initially appeared to be a major hardware wallet breach has grown into a far larger forensic investigation as new evidence continues reshaping its scale.

Initial findings linked the exploit of Coldcard to 4,585 addresses in three waves and the theft of about 1,367 Bitcoin [BTC] worth roughly $88.6 million.

Later on, investigators identified another 1,912 affected addresses, which increased losses by 207.73 BTC and showed that all stolen coins remained unspent.

Source: Galaxy Research

That behavior suggested the attacker prioritized consolidating funds instead of rushing to liquidate them. Since then the investigation has grown again. Confirmed losses now total more than 1,596 BTC worth more than $100 million across roughly 7,300 addresses.

Galaxy Research also identified 14 smaller related incidents, pushing suspected losses toward 2,000 BTC, or nearly $130 million. This exploit stands out as one of Bitcoin’s most serious failures related to custody security and raises broader questions about the resilience of hardware wallets.

Blockchain data strengthens the investigation

As the investigation broadens, blockchain forensics are also revealing how the stolen Bitcoin has been managed after the attacks.

The three confirmed theft waves remain the foundation of the case, while a fourth suspected wave could lift total losses to 2,055 BTC, or roughly $130 million, if victims confirm its inclusion.

More importantly, fund movements continue following a remarkably consistent pattern.

Source: Galaxy Research

Ninety percent of the stolen Bitcoin remains untouched. Furthermore, each of the coins transferred through Wave 1, Wave 2, and Wave 3 sits in its receiving addresses.

That inactivity has strengthened investigators’ confidence in mapping attacker-controlled wallets and identifying additional linked addresses.

Meanwhile, newly discovered smaller theft events suggest opportunistic actors may have exploited similar conditions after the initial compromise.

As blockchain attribution improves, investigators are providing verified addresses to law enforcement, exchanges, and compliance firms, increasing the chances of tracking future movements while limiting opportunities to cash out.

The exploit challenges confidence in self-custody

Beyond exposing the exploit’s technical scope, the incident has also challenged one of Bitcoin’s longest-standing assumptions about self-custody.

The incident did not expose a flaw with self-custody. Instead, it exposed the need for well-designed wallets and independent entropy generators. It further supports best practices for user protection, including using multisig and utilizing better backup methods.

In response, Coinkite released emergency firmware, paused shipments, and urged users to generate entirely new seeds before moving funds. However, software updates cannot repair previously generated weak seeds.

Whether confidence fully recovers will depend on transparent security reviews, verifiable randomness, and clearer industry standards. The exploit may therefore reshape how users secure Bitcoin rather than discourage self-custody altogether.


Final Summary

  • The Coldcard exploit has surpassed $100 million, marking a major hardware wallet security breach.
  • This incident is driving stronger self-custody security and wallet protection practices.
Disclaimer: AMBCrypto's content is meant to be informational in nature and should not be interpreted as investment advice. Trading, buying or selling cryptocurrencies should be considered a high-risk investment and every reader is advised to do their own research before making any decisions.

Muriuki Lazaro

Journalist

Muriuki Lazaro is a on-chain data analyst with a B.Sc. in Data Science. Muriuki specializes in dissecting complex on-chain data into clear and accurate insights for readers in the crypto ecosystem, with a particular focus on Bitcoin.

AMBCrypto was founded in 2018 with a mission to simplify and bring the latest blockchain and cryptocurrency news to our readers. We have quickly grown into the digital news source for an emerging generation of cryptocurrency enthusiasts, reaching more than a million readers on a monthly basis, across the globe.