Coldcard exploit drains $89M, exposing hardware wallet security gaps

A weekend that was supposed to prove crypto’s most conservative security promise instead turned into one of the year’s costliest wake-up calls. Roughly $89 million was drained from hardware wallets tied to a widely used device called Coldcard, according to reporting from Fox Business, reigniting a debate that touches on the very core of hardware wallet security: is offline storage really as untouchable as the industry has always claimed?
Key takeaways
- Approximately $89 million was drained from hardware wallets over a recent weekend, tied to an exploit affecting the Coldcard device.
- CoinDesk first reported the theft on July 31, 2026, at around $38 million and nearly 600 bitcoin, a figure that grew as the exploit spread.
- Fox Business later reported the attack had drawn from more than 1,200 addresses, pushing losses toward $89 million.
- Cold storage is traditionally viewed as the safest way to hold crypto, but the incident shows no single device guarantees full protection.
- Layered defenses — independent audits, bug bounties, revocable approvals and verifiable code — are now being framed as the real safeguard, not the hardware itself.
Massive $89 Million Loss from Hardware Wallets Challenges Cold Storage Security
The numbers tell a story that grew worse by the day. CoinDesk reported on July 31, 2026, that a software bug in Coldcard, a popular hardware wallet, had already led to the theft of nearly 600 bitcoin worth roughly $38 million, and the total was still climbing at the time of publication. Just days later, Fox Business put the running toll at up to $89 million, spread across more than 1,200 compromised addresses.
… Continue reading the full article at the original source below.


