The Safest Way to Hold Bitcoin Has Now Lost 116 Million Dollars, and It's Still Rising
Hardware wallets are meant to be the gold standard of crypto safety, coins kept offline where hackers cannot reach them. A flaw in the popular Coldcard device shattered that assumption. A fourth wave of theft detected Monday pushed losses to roughly 116 million dollars in Bitcoin across more than 5,200 wallets, and the attacks are ongoing.
Hardware wallets are meant to be the gold standard of crypto safety, coins kept offline on a small device where online hackers cannot reach them. A flaw in the widely used Coldcard wallet has shattered that assumption. What began as a 38 million dollar sweep at the end of July has climbed through four waves of attacks to roughly 116 million dollars of Bitcoin drained from more than 5,200 wallets, and researchers warn the theft is still ongoing.
The cause was a long-buried software bug. A firmware change back in 2021 quietly weakened the randomness the device used to generate a wallet's secret keys, leaving them far more predictable than owners believed, so an attacker could eventually reproduce the keys and sweep the funds. The device looked secure the entire time. The weakness was invisible to the people relying on it.
The maker has moved to contain it. Coldcard's manufacturer confirmed the vulnerability, halted shipments and destroyed remaining units carrying the affected firmware, while researchers are urging anyone still holding single-key funds on one of the devices to move their coins immediately. A recall cannot undo the theft. It can only stop the next one.
The irony cuts deep. Self-custody, holding your own keys rather than trusting an exchange, is the core promise of Bitcoin, and hardware wallets are how careful people practise it, so an exploit that punishes exactly the most security-conscious holders strikes at the movement's central idea. The people who did everything right were the ones exposed. That is what makes this frightening.
The reaction says a lot about trust. After the FTX collapse investors fled exchanges for self-custody, and now some are doing the reverse, sending coins back to exchanges because a trusted device failed them, which shows how quickly confidence can swing from one model of safety to the other. There is no risk-free way to hold this asset. Every option simply moves the danger somewhere else.
So the device marketed as bitcoin's safest hiding place became, for thousands of owners, the reason their coins are gone, and the tally keeps climbing. More than 116 million drained, 5,200 wallets hit, four waves and counting. Self-custody was supposed to mean nobody could touch your coins. It turns out the wallet still had to be built correctly.