NewsCryptoReported Coldcard Hardware Wallet Flaw Linked to Theft of 1,816 BTC Worth $116 Million

Reported Coldcard Hardware Wallet Flaw Linked to Theft of 1,816 BTC Worth $116 Million

Author: Hokanews·

Key Takeaways

  • An X post attributed the theft of 1,816 BTC, valued at $116 million, to a vulnerability in Coldcard hardware wallets.
  • The post provided no details on when the alleged theft occurred, how the flaw was exploited, or which Coldcard models or versions might be affected.
  • Coldcard is a Bitcoin hardware wallet produced by Coinkite that supports fully air-gapped operation, with transactions transferred via microSD card.
  • The report gave no indication of whether the stolen Bitcoin was recovered, whether authorities are investigating, or how many users were impacted.
  • Large documented crypto thefts have typically involved centralized platforms, such as the February 2025 Bybit breach of roughly $1.5 billion in ether attributed by the FBI to North Korea's Lazarus Group.
Reported Coldcard Hardware Wallet Flaw Linked to Theft of 1,816 BTC Worth $116 Million

A post on X has attributed the reported theft of 1,816 BTC — valued in the post at $116,000,000 — to a flaw in Coldcard hardware wallets. The post identified the hardware wallet vulnerability as the cause of the loss but offered no additional technical detail on the flaw itself, the circumstances surrounding the incident, or the identities of the users affected.

Reported Coldcard Security Incident

Coldcard is a hardware wallet designed to provide offline storage and signing capabilities for Bitcoin. Such devices are generally used to keep private keys isolated from internet-connected machines, reducing exposure to certain forms of online attack. The wallet line is produced by Coinkite and supports fully air-gapped workflows, in which transactions are moved to and from the device on a microSD card rather than through a direct computer connection.

According to the information shared on X, a flaw involving Coldcard hardware wallets was associated with the theft of 1,816 BTC, which the post valued at $116,000,000.

No further information was provided about when the alleged theft occurred, how the vulnerability was exploited, or whether a particular Coldcard model or version was affected. The post also did not state whether the reported vulnerability had been identified, disclosed, or addressed by the manufacturer.

Hardware wallets from multiple vendors have been the subject of independent security research over the years, with public disclosures covering firmware weaknesses, supply-chain risks, and physical or side-channel attacks, and manufacturers have typically responded with firmware updates or revised hardware designs. In this case, the absence of technical detail means the precise mechanism behind the reported loss cannot be established from the information provided, and the available claim remains limited to the reported connection between a Coldcard flaw and the loss of the stated amount of Bitcoin.

Self-Custody Places Security Responsibility on the Holder

Cryptocurrency self-custody allows users to control their digital assets directly rather than relying on a centralized exchange or another third-party custodian. That structure can provide greater control over private keys, but it also places security responsibilities on the asset holder.

Hardware wallets are designed to address some of the risks of storing private keys on internet-connected computers and smartphones. Transactions are generally signed on the hardware device while sensitive key material remains isolated from the connected computer.

Hardware-based custody, however, does not eliminate all security risks. Vulnerabilities can potentially arise from device software, firmware, physical access, transaction-signing processes, or interactions with other systems, and the specific risks depend on the nature of the individual vulnerability.

The reported Coldcard incident highlights the importance of understanding how custody systems protect private keys and how security weaknesses can affect digital assets when users maintain direct control of their funds.

Bitcoin Theft Underscores Scale of Potential Losses

The reported loss of 1,816 BTC illustrates the financial consequences that can follow a security failure involving a large cryptocurrency balance. At the valuation cited in the X post, the stolen Bitcoin was worth $116,000,000. Publicly reported thefts of this size attributed to a personal hardware wallet flaw are less common than breaches of centralized platforms: the largest documented crypto thefts have typically involved exchanges and custodians, most notably the February 2025 breach of the Bybit exchange, in which roughly $1.5 billion in ether was stolen and attributed by the FBI to North Korea's Lazarus Group.

Bitcoin transactions are generally designed to be irreversible once confirmed on the network. Recovering assets after an unauthorized transfer can therefore be difficult, particularly when the recipient's identity or location is unknown.

The report did not indicate whether any of the 1,816 BTC had been recovered or whether authorities or other parties were investigating the alleged theft, and it provided no information on the number of users affected.

For Bitcoin holders using self-custody solutions, the incident is a reminder that securing private keys involves risks that extend beyond simply keeping a device offline. Determining the broader implications for Coldcard users would require the technical details of the reported vulnerability — its cause and its scope — which have not been disclosed. Key open questions include whether Coinkite confirms or disputes the report, whether a firmware or hardware fix follows, and whether on-chain analysis or law enforcement activity publicly corroborates the loss.

Source: Hokanews