
Coldcard Hardware Wallet Exploit Steals $114M in Bitcoin, Most Funds Remain Unmoved
A software vulnerability in Coldcard hardware wallets has resulted in the theft of approximately 1,789 bitcoin worth $114.7 million, according to Galaxy Research analysis. More than 87% of the stolen funds remain in attacker-controlled addresses, suggesting either operational delays or a potential recovery window.
Written by CoinArticle’s AI Newsroom · from 3 cited sources. How we work
Story Updates
- Updated Aug 25, 2026, 11:02 AM: Galaxy Research traced total losses to $114.7 million across 1,789 BTC; 87% of stolen funds remain unmoved in attacker addresses.
Updated Theft Scale and On-Chain Status
Research from Galaxy traced 1,789.28 BTC stolen across 8,865 Coldcard addresses to a total loss of $114.7 million, significantly higher than initial estimates of 600 BTC. Notably, 1,561 BTC—or 87% of the stolen amount—has remained unmoved since the theft, according to Crypto.news reporting. The stationary funds suggest either the attacker is not yet converting assets or faces operational constraints in liquidating such a large sum without detection.
The Exploit and Initial Response
A software vulnerability in Coldcard hardware wallets enabled the attack. Bitcoin Magazine reported that experts analyzing the breach believe the attacker likely used services from a major blockchain infrastructure provider, though the specific firm was not named in available reporting. Security researchers have advised Coldcard users to move their funds immediately as a precaution.
Implications for Self-Custody and Asset Management
The exploit has reignited debate over the security and practicality of self-custody for retail investors. CoinDesk reported that the incident is prompting some market participants to reconsider whether managing private keys directly has become too risky for everyday users, potentially driving migration toward regulated custodial solutions including spot Bitcoin ETFs. The scale of the loss—now confirmed at nearly $115 million—represents one of the largest known breaches tied to a consumer hardware wallet vulnerability, underscoring both the technical complexity and operational risk involved in self-directed key management.
Why It Matters
For Traders
The presence of $100M+ in unmoved stolen BTC creates uncertainty around potential forced liquidation events and regulatory intervention timing.
For Investors
The severity and scale of losses strengthen the case for custodial solutions and may accelerate institutional preference for regulated spot ETFs over self-custody.
For Builders
Wallet developers face intensifying pressure to implement supply-chain security hardening and real-time transaction monitoring in key management infrastructure.
This article is for information only and is not financial advice. Read the full disclaimer.





