The reported figure of 594 BTC moved in a single short window was first detailed in reporting on the sweep . At this stage the event is best described as a reported incident rather than a fully documented exploit postmortem.
A reported Coldcard-related incident saw 594 BTC drained in roughly 25 minutes, a rapid sweep that has put Bitcoin self-custody users on alert. The scale and speed of the reported drain, rather than any confirmed root cause, are what make the event stand out.
WHAT TO KNOW
- 594 BTC was reportedly drained during the incident.
- The reported drain unfolded in about 25 minutes.
The reported figure of 594 BTC moved in a single short window was first detailed in reporting on the sweep. At this stage the event is best described as a reported incident rather than a fully documented exploit postmortem. For related coverage, see Upbit to List Conflux (CFX) in KRW, BTC and USDT Markets.
The compressed timeline matters. A drain completed in roughly 25 minutes leaves little room for detection or intervention once funds begin moving, which is a core reason the story has drawn attention from Bitcoin holders. For related coverage, see Strategy to Sell Bitcoin, Slow New BTC Buying.
What “Coldcard-related” does and does not confirm
The framing is deliberately cautious. Describing the event as “Coldcard-related” signals a connection to the hardware wallet’s usage context, not a confirmed statement that the device itself was compromised. For related coverage, see Strategy Posts $8.22 Billion Q2 Loss After Bitcoin Pullback.
Attribution wording carries weight in security coverage. Until a specific attack path is established, the label leaves room for multiple interpretations, including how the wallet was set up or used rather than a flaw in the product.
Coinkite, the maker of Coldcard, has previously issued its own device guidance, including a seed-generation warning for the Coldcard Mk3. That history shows why precise language around any wallet incident matters, and why this report should not be read as confirmation that Coldcard was hacked.
What is confirmed here is narrow: a large BTC drain occurred and has been publicly connected to a Coldcard context. The root cause remains an open question.
Why a fast drain raises the stakes for self-custody
A 594 BTC loss is material enough on its own to command the attention of Bitcoin holders and to prompt scrutiny of custody practices. The size alone places this among the incidents self-custody users watch closely.
The 25-minute pace sharpens those concerns. Rapid fund movement compresses the window for a holder to notice unusual activity and respond, which is why detection speed becomes central to how readers assess their own risk.
Security incidents that drain wallets are not unique to Bitcoin hardware. Recent cases such as a malicious governance proposal that drained BONK treasury funds and an MEV bot drained in a counter-MEV honeypot exploit underline how varied the attack surface across crypto has become.
For now, the practical takeaway stays tied to the incident rather than the price chart: the combination of a large BTC sum and a short drain window is why this story matters even before a full technical explanation is available.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
