An active and escalating security breach targeting users of Coldcard hardware wallets has now drained an estimated $114 million worth of Bitcoin from victims, with no sign that the theft has been halted. The breach, which has shaken confidence in one of the most widely trusted self-custody devices in the Bitcoin ecosystem, represents one of the largest hardware wallet-related losses on record — and the damage is still mounting.

Hardware wallets like Coldcard have long been positioned as the gold standard for Bitcoin self-custody. The premise is straightforward: by keeping private keys on an air-gapped physical device rather than an internet-connected software application, users are supposed to be insulated from the remote exploits and phishing campaigns that regularly plague hot wallets and exchange accounts. A breach of this magnitude, therefore, is not merely a financial story — it is a direct assault on the foundational security argument that underpins self-custody as a practice.

An Ongoing Drain, Not a Closed Incident

What makes this situation particularly alarming is the active, continuous nature of the theft. As of the time of reporting, Bitcoin wallets are still being drained. This is not a post-mortem analysis of a contained breach — it is a live incident unfolding in real time, with the total stolen figure still climbing past the $114 million threshold. The persistence of the attack suggests either that the underlying vulnerability has not yet been fully identified and patched, that victims have not yet been notified or have not acted on warnings, or that the attack vector operates in a way that makes rapid intervention difficult.

For Bitcoin holders who rely on Coldcard devices, the immediate and practical question is whether their own funds are at risk. The fact that the theft is ongoing and the mechanisms behind it have not been publicly detailed in full creates an environment of acute uncertainty. Self-custody, which demands that individual users take full personal responsibility for the security of their holdings, becomes exponentially more stressful when the tools designed to enable that security appear compromised.

What This Does to Hardware Wallet Trust

The hardware wallet market has operated for years on a bedrock assumption: that physical possession of a signing device equals security. Coldcard, manufactured by Coinkite, has cultivated a reputation as one of the most security-focused devices available to retail and professional Bitcoin holders. Its user base skews toward technically sophisticated, long-term holders — precisely the demographic least likely to fall for conventional social engineering attacks. If this demographic is being victimized at scale, it forces a hard reassessment of what the threat model for hardware wallets actually looks like in 2026.

The $114 million figure is significant not just as a dollar amount but as a signal. It implies a large number of affected wallets, a systematic exploitation methodology rather than isolated incidents, and a level of coordination on the part of the attackers that goes well beyond opportunistic theft. Whether the attack vector involves a supply chain compromise, a firmware vulnerability, a seed phrase extraction method, or something else entirely, the scale demands a transparent and urgent response from Coinkite and from the broader Bitcoin security community.

The Wider Industry Implications

Events of this nature tend to have cascading effects. Exchange custody services, which Coldcard's core user base has historically avoided on ideological grounds, may see renewed inflows from users spooked by the breach. Competing hardware wallet manufacturers will face both opportunity and scrutiny — opportunity to attract displaced users, and scrutiny as the industry as a whole comes under pressure to demonstrate that its security guarantees are real. Regulatory observers, who have long argued that self-custody creates consumer protection risks, will inevitably point to a $114 million ongoing theft as evidence in favor of stricter oversight frameworks.

For the Bitcoin community specifically, this incident complicates the "not your keys, not your coins" narrative at a particularly sensitive moment. That philosophy has driven billions of dollars out of centralized custodians and into hardware devices. A breach of this scale does not invalidate self-custody as a concept, but it does demand honest reckoning with the fact that self-custody security is only as strong as the hardware, firmware, and operational practices supporting it — all of which can fail.

What This Means

Until Coinkite provides a full technical disclosure of the attack vector and confirms that it has been neutralized, every current Coldcard user faces a live threat assessment decision. The $114 million in losses — and the fact that wallets are still being actively drained — makes this one of the most consequential Bitcoin security events in recent memory. The hardware wallet industry's credibility, and the practical viability of retail self-custody at scale, now hinge on how quickly and how transparently this crisis is resolved. Users holding funds on any Coldcard device should treat this as an active emergency until definitive guidance says otherwise.

Written by the editorial team — independent journalism powered by Bitcoin News.