The Coldcard hardware wallet exploit has now cost users more than $116 million, spread across four separate attack waves. A fourth wave is still active, according to the company behind the device, Coinkite, which described the last three days as among the hardest in its history. The initial estimate of $30 million in stolen funds has more than tripled in less than a week.
How the losses grew
What started as a $30 million theft quickly escalated. Attackers found a way to drain funds from Coldcard wallets, and they didn't stop. Three more waves followed, each adding to the total. Coinkite hasn't detailed the exact mechanism behind the exploit, but the company confirmed the ongoing fourth wave continues to pull money out of affected wallets. Users are urged to move funds immediately if they haven't already.
Coinkite's response
Coinkite said the past three days have been among the hardest in the company's history. The firm has been working to contain the damage and communicate with users. It hasn't announced a fix yet, but it's clear the situation remains fluid. The company didn't say how many wallets or users are affected, but the dollar figure suggests a significant number of people have been hit.
What users should do now
Anyone with a Coldcard wallet should assume their funds are at risk. The fourth wave is still draining wallets, so waiting isn't an option. Coinkite has advised users to transfer their crypto to a different wallet or exchange until the exploit is patched. The company hasn't provided a timeline for a fix, but the ongoing losses make it urgent.
The $116 million figure is likely to climb. With the fourth wave still active, the final tally could be much higher. Coinkite hasn't said when the attack might stop or what steps it's taking to prevent further waves. For now, the only safe move is to move.



