A third wave of thefts from Coldcard Bitcoin wallets has been detected, with approximately 1,367 BTC stolen from 4,585 addresses. The total value of the losses is estimated at $88 million. The incidents mark a continuing security issue for the popular hardware wallet, which is designed to keep private keys offline.
How the thefts unfolded
The latest wave follows earlier incidents, though details on the exact method remain unclear. Users reported unauthorized transactions from their Coldcard devices, which are meant to be air-gapped and resistant to remote attacks. The pattern suggests a systematic compromise rather than isolated user error. Previous waves hit smaller numbers of addresses; this one is the largest by far.
What Coldcard users are seeing
Affected addresses span a wide range of holders. Some users noticed funds moving without their authorization, while others discovered their wallets had been drained entirely. The wallet manufacturer has not yet issued a public statement explaining the root cause. Forums and social media are filled with frustrated owners who say they followed all recommended security steps.
The broader context
The thefts come at a time when hardware wallets are considered a gold standard for secure Bitcoin storage. The repeated incidents raise questions about the security of the supply chain or potential vulnerabilities in the device's firmware. Coldcard has built a reputation on being open-source and verifiable, but that hasn't stopped the losses. The timing isn't great — Bitcoin's price has been volatile, and many holders are already on edge.
Coldcard has not announced a patch or a recall. Users are advised to move funds to new wallets generated on a clean device. The company faces pressure to provide a detailed post-mortem. The next expected update from Coldcard is a firmware release, though no date has been set. Until then, the affected addresses remain a stark reminder that even cold storage isn't immune.




