New victim data is coming into focus on the Coldcard hardware wallet exploit, one of the largest self-custody security failures in Bitcoin's history. Galaxy Research analyst Alex Thorn reviewed reports from 250 affected users and found a median loss of 1.022 BTC per victim, with the average loss running far higher at 4.04 BTC — a gap that points to a handful of large holders absorbing an outsized share of the damage. Looked at by address rather than by victim, the median loss narrows to 0.014 BTC while the mean sits at 0.212 BTC, and at least one address lost as much as 58.97 BTC.
Confirmed losses from the exploit now stand at $111 million, though Bitcoin Magazine reports the true figure is likely higher and could ultimately land above $130 million once all affected addresses are accounted for. The theft began with an initial $35 million taken last Thursday before continuing in waves throughout the following weekend.

A Firmware Bug Dating to 2021
At the root of the exploit is a flaw in Coldcard Mk3 devices running firmware starting with version 4.0.1, released in March 2021. Rather than relying on the device's dedicated hardware true-random-number generator to create seed phrases, affected units silently fell back on a weaker software-based pseudorandom number generator. That weakness made it possible for attackers to guess victims' seed phrases outright, bypassing the entire point of offline, hardware-based key storage. Notably, the median age of stolen coins was 3.5 years, and 88% of the funds taken had sat untouched for at least a year — evidence that many victims were long-term holders who treated their Coldcard as a permanent, low-maintenance vault rather than something to monitor closely.
Coinkite, the company behind Coldcard, acknowledged that the bug "silently went unnoticed" and that "its potential impact grew with every release" as more users adopted the affected firmware over the following years. The company has urged remaining users to update their software or move funds to newly generated addresses immediately.
The Costliest Hardware Wallet Failure on Record
Blockchain analytics firm TRM Labs has described the incident as the largest hardware wallet exploit of 2026, with the attacker moving roughly 1,816 BTC out of more than 5,200 affected addresses across four separate waves since the exploit began. That puts it among the year's biggest crypto hacks overall — trailing only a couple of larger incidents — at a time when total crypto losses to hacks in 2026 have already surpassed $1.2 billion across 276 separate incidents. By comparison, the roughly two dozen DeFi protocol exploits recorded over the same recent stretch totaled a combined $132.2 million, meaning a single hardware wallet flaw did more damage than a full month of DeFi hacks combined.
Related: Bitcoin Wallet Activity Spikes as Coldcard Hack Fallout Continues
The episode is likely to reignite scrutiny of how hardware wallet makers handle firmware updates and randomness generation, given that the category has long been marketed to Bitcoin holders specifically as the safest way to avoid exactly this kind of loss.