Coldcard halts shipments as hackers drain $86.62 million in Bitcoin
CoinKite halted Coldcard shipments and destroyed vulnerable units after hackers drained $86.62 million in Bitcoin. A fourth wave of attacks is currently underway, with $24.53 million stolen in recent transactions. Users are urged to migrate funds immediately.

*this image is generated using AI for illustrative purposes only.
CoinKite, the maker of Coldcard hardware wallets, has halted all shipments and destroyed remaining inventory with vulnerable firmware after a coordinated cyberattack drained approximately 1,367.59 Bitcoin (BTC), worth $86.62 million at current prices. The breach exposes critical vulnerabilities in self-custody solutions, prompting urgent warnings for users to migrate funds immediately to prevent further exploitation.
The incident involves multiple waves of theft targeting the Coldcard wallet ecosystem. According to a live dashboard tracking the exploit, a total of 1,367.59 BTC has been siphoned from linked wallets. Alex Thorn, Head of Research at Galaxy Research, identified that hackers are launching a fourth coordinated attack. This latest wave has already pilfered 388.93 BTC, valued at $24.53 million, from 462 addresses across 218 transactions. Thorn alerted users on X on August 3, 2026, noting that pending transactions in the mempool indicate ongoing siphoning efforts.
Immediate Mitigation Steps
Coldcard confirmed the vulnerability on August 2, 2026, stating it halted shipments upon confirmation of the flaw. The company destroyed all remaining units with the affected firmware installed at its facilities. Customers who had already received orders were contacted directly via email with an advisory and migration steps. "Right now, our full focus is helping affected users migrate safely," Coldcard said.
Thorn urged users to move funds off the Coldcard wallet immediately, recommending high transaction fees to prioritize rescue transactions ahead of the attackers'. He warned that users whose addresses appear in the attack list have only minutes to engage in a fee race to secure their funds.
Industry Response and Risks
Binance co-founder Changpeng "CZ" Zhao highlighted the inherent risks of self-custody in response to the drains. On August 1, 2026, Zhao noted that bug fixes cannot retroactively secure previously generated wallets and that developers have no way to reach users on air-gapped devices. "I'm a believer in self-custody, but it puts the burden on you," Zhao said, emphasizing that wallets remain open to hackers until users manually intervene.
The incident underscores that hardware wallets, which store private keys offline to protect against malware, are not foolproof. Ledger, another major industry player, faced a sophisticated hacking incident in 2023 resulting in the theft of approximately $484,000 in assets. Benzinga reached out to CoinKite regarding safeguards, liability protections, or contingency measures planned following this incident.
Market Impact
At the time of writing, Bitcoin was trading at $63,071.73, down 0.40% in the last 24 hours, according to Benzinga Pro data. The breach raises broader concerns about security protocols in decentralized finance infrastructure.
| Metric | Value |
|---|---|
| Total BTC Drained | 1,367.59 BTC |
| Total Value Lost | $86.62 million |
| Fourth Wave BTC | 388.93 BTC |
| Fourth Wave Value | $24.53 million |
| Affected Addresses | 462 |
| Transactions | 218 |
| Current BTC Price | $63,071.73 |
What the Numbers Show
The concentration of losses in the fourth wave—accounting for nearly 29% of the total drained value ($24.53 million of $86.62 million)—suggests that attackers are actively exploiting the vulnerability in real-time rather than relying solely on initial access. The rapid succession of 218 transactions affecting 462 addresses indicates a highly automated script capable of identifying and draining compromised wallets faster than many users can react, highlighting the critical importance of immediate fee-racing mitigation strategies advised by researchers.
How will this breach impact regulatory scrutiny on hardware wallet manufacturers regarding liability for firmware vulnerabilities?
Will institutional investors reconsider their self-custody strategies in favor of multi-signature or custodial solutions following this incident?
What specific technical safeguards might CoinKite implement in future firmware updates to prevent similar real-time exploitation vectors?

































