More than $88 million in crypto assets have been drained from Coldcard hardware wallets, with the exploit continuing to move funds. This is a direct hit to cold storage's core promise—that keeping keys offline keeps them safe.
Coldcard, developed by Coinkite, is a Bitcoin-focused hardware wallet built to isolate private keys from internet-connected devices. Its security model runs on air-gapped transactions and multi-signature capabilities. That makes this breach hurt more, not less.
On-chain data shows the stolen funds include Bitcoin and other digital assets, with transactions routed through multiple intermediary addresses. Analysts are actively tracking the movement, observing patterns consistent with a coordinated draining operation.
The $88 million figure places this among the larger crypto thefts of 2026. It doesn't reach the scale of the $625 million Ronin Bridge hack in 2022, but it is one of the largest breaches ever recorded against a dedicated hardware wallet—a device class people buy specifically because they don't trust anything else.
The attack vector remains under investigation. Whether this involved a supply chain compromise, malware targeting device firmware or a zero-day vulnerability, nobody has confirmed it publicly yet.
Coinkite has not issued a detailed public statement on the exploit's mechanism or specific steps for affected users. That silence is making things worse for the self-custody community right now.
If you're holding on a Coldcard, the immediate steps are clear: audit device integrity, verify firmware authenticity and consider moving to a multi-signature setup using diverse hardware. Spreading holdings across different cold storage solutions cuts single-point-of-failure risk.
The drain is still active. Attackers either maintain live access or have automated the transfer process. Blockchain analytics firms are working to identify destination wallets and trace the perpetrators.
This will force harder questions about hardware wallet manufacturing, firmware update pipelines and supply chain security. The industry has treated air-gapped cold storage as the ceiling of individual security. This breach says it isn't.


