A Coldcard wallet exploit has been linked to the theft of more than 1,778 Bitcoin worth roughly $112 million, according to unconfirmed reports circulating across the crypto community. The incident, still unverified in its technical specifics, has renewed scrutiny of hardware wallet security and the self-custody assumptions many Bitcoin holders rely on.
The reported loss centers on Coldcard, the hardware wallet built by Coinkite. As of publication, the exploit method has not been independently confirmed, and the figures tied to the theft should be treated as preliminary rather than established fact. For related coverage, see Bitcoin Prices Rally After $116 Million Coldcard Hack.
What is known about the Coldcard wallet exploit
The core claim is that a flaw associated with Coldcard devices allowed an attacker to drain more than 1,778 BTC. The scale of that reported figure is what makes the event significant for hardware wallet users, who typically treat cold storage as the strongest line of defense against theft.
Coinkite has previously issued security guidance for its devices, including a seed-generation warning for the Coldcard Mk3, underscoring that even purpose-built hardware wallets carry operational risks that depend on how users generate and protect their keys.
Discussion of the reported theft has spread through crypto research circles on social platforms, including commentary shared on X. That chatter has not been substantiated by a confirmed technical disclosure at this time.
How the reported theft could affect self-custody trust
A loss of this reported size, if confirmed, would prompt immediate risk reassessment among Coldcard owners. Hardware wallet incidents tend to trigger fast, community-wide checks of firmware versions, seed handling, and device provenance.
The episode also highlights the distinction between device-level security and user operational security. A hardware wallet can be sound while a compromise still occurs through seed exposure, supply-chain tampering, or flawed setup, which is why the exact exploit path matters so much here.
The relevance extends beyond a single brand. Earlier coverage of the Coldcard firmware exploit that could drain $100M and reporting that a Coldcard exploit was linked to a $116 million hack show how quickly such claims escalate and how uneven the loss estimates remain across accounts.
What details matter most as the story develops
The most important open question is whether the exploit itself has been confirmed or disputed by Coinkite or independent security researchers. Without a verified method, the scope and the affected-user count cannot be reliably established.
Readers should also watch for clarity on the exposure window, meaning when the vulnerability first became exploitable and how long funds were at risk. The Coldcard exploit reaching its fifth day amid security concerns and shifting estimates that the Coldcard Bitcoin hack neared $114 million in potential losses illustrate how the reported totals have moved as the situation evolves.
Remediation and investigation updates will be decisive. Confirmation of the attack vector, guidance for affected users, and any official response from Coinkite are the details that will determine how much of the current reporting holds up.
Additional source references: source document 1.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
