Loading market data...

Coldcard Exploit Hits 4,585 Wallets, $88.6M in Bitcoin Still in Attacker's Hands

Coldcard Exploit Hits 4,585 Wallets, $88.6M in Bitcoin Still in Attacker's Hands

A security incident tied to Coldcard hardware wallets has compromised 4,585 wallets, with the attacker still holding $88.6 million in stolen Bitcoin as of this week. The exploit, which investigators suspect is linked to Coldcard devices, has not yet seen the funds moved — leaving a rare window for potential recovery efforts.

The scale of the breach

The numbers are stark: 4,585 wallets drained, $88.6 million in Bitcoin sitting in the attacker's control. That's roughly 1,200 BTC at current prices. The attacker hasn't attempted to launder or cash out the funds yet, which is unusual for a heist of this size. Typically, stolen crypto gets shuffled through mixers or exchanges within hours. Here, the Bitcoin has stayed put.

Coldcard under scrutiny

Investigators are zeroing in on Coldcard hardware wallets as the likely entry point. The company, known for its focus on security and air-gapped signing, hasn't publicly confirmed a vulnerability. But the pattern of affected wallets — all tied to Coldcard devices — has made the connection hard to ignore. If a firmware or supply-chain flaw is to blame, it would be one of the most significant hardware wallet exploits in years.

Wider investigation underway

The probe is expanding. Investigators are linking more wallets and Bitcoin addresses to the broader attack, suggesting the initial count of 4,585 may grow. Blockchain analysis firms are combing through transaction histories to map the full scope. The attacker's decision to hold the funds could mean they're waiting for the heat to die down — or that they're unable to move the coins without triggering alarms.

What happens next

For now, the stolen Bitcoin remains traceable. Every transaction from those wallets will be watched. Coldcard users are left wondering whether their devices are safe, and the broader hardware wallet market is bracing for fallout. The next concrete step: investigators are expected to release a list of compromised addresses in the coming days, which could help victims confirm losses and push exchanges to blacklist the funds.