A reported bug in the Coldcard hardware wallet has been linked to a Bitcoin theft with losses that could reach as much as $130 million, according to early reporting on the incident.
A reported bug in the Coldcard hardware wallet has been linked to a Bitcoin theft with losses that could reach as much as $130 million, according to early reporting on the incident.
A reported bug in the Coldcard hardware wallet has been linked to a Bitcoin theft with losses that could reach as much as $130 million, according to early reporting on the incident. The connection remains a reported claim rather than a fully proven conclusion, and key technical details about how the alleged Coldcard bug enabled the theft have not been publicly confirmed.
WHAT TO KNOW
The incident centers on Coldcard, a Bitcoin-only hardware wallet built by Coinkite, and a security flaw that reporting has tied to the theft of customer funds. Coverage of the losses possibly reaching $130 million appeared in The Block’s daily briefing dated August 4, 2026. For related coverage, see Trump Says US May Buy Sizable Amounts of Bitcoin.
This article covers a reported link between the bug and the theft, not a settled forensic finding. The research available at the time of writing does not include a confirmed timeline, a verified attacker profile, or a definitive figure for funds moved on-chain.
Coinkite has previously issued guidance around seed generation on its devices, including a warning covering Coldcard Mk3 seed generation. Whether that specific advisory relates to the current incident has not been established in the available evidence.
The basis for connecting the bug to the theft comes from incident reporting rather than a published root-cause analysis. A cyberattack framing of the losses was described by The Record’s coverage of the Bitcoin theft.
The distinction matters for readers: at this stage the link reads as an ongoing investigation, not confirmed direct evidence that a single Coldcard flaw signed unauthorized transactions. The technical mechanism, whether it involved seed generation, key extraction, or transaction signing, is not verified in the material reviewed here.
Follow-on reporting has tracked the movement of funds after the incident. Coverage has documented how stolen Bitcoin from the Coldcard hack began moving through a mixer, and how new Bitcoin addresses jumped as funds were transferred in the aftermath.
Coldcard holders should watch for official guidance from Coinkite on firmware, device checks, or any mitigation steps tied to the specific flaw. The affected versions, setup conditions, and exact user base remain unclear in the available evidence, so caution about which devices are at risk is warranted.
The market response has included defensive custody moves. Reporting indicates that roughly $15 billion in Bitcoin was moved to safety after the hack, and that Coldcard has since added new security measures following the exploit.
For the Bitcoin network itself, an incident of this type is a custody and key-management event rather than a protocol failure. The theft, if confirmed at the reported scale, reflects endpoint and hardware-wallet risk at the UTXO-control layer, not a weakness in Bitcoin’s consensus rules, mining, or difficulty adjustment, all of which continue to operate independently of any single wallet vendor.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.
Quick access to the site tools and map-driven utility pages.
Follow the core desks readers use most across Bitcoin, altcoins, mining, events, and sponsored coverage.
© 2026 BitcoinInfoNews.com. All rights reserved.
Independent Bitcoin and crypto coverage with public trust, policy, and newsroom pages available sitewide.