Coldcard Wallet Losses Could Reach $114M Amid Fourth Sweep
Suspected exploits targeting Coldcard hardware wallets may have drained nearly $114 million, with signs of a possible fourth wave of fund sweeps.
A wave of suspected exploits targeting users of Coldcard hardware cryptocurrency wallets may have pushed total losses close to $114 million, according to reporting by CoinDesk, as investigators track what could be a fourth coordinated sweep of victim funds. The scale of the incident, if confirmed, would rank it among the more significant hardware wallet security events in recent memory, raising urgent questions about the safety of cold storage devices long marketed as the gold standard for securing digital assets.
Coldcard wallets are physical devices designed to store private keys offline, providing an air-gapped layer of protection against online hackers. The emergence of repeated fund-sweep events suggests attackers may have obtained access to private keys or seed phrases through a method that bypasses the device's standard security architecture, though the precise attack vector had not been publicly confirmed at the time of reporting.
Read more Strategy Sells $105M in Bitcoin, Buys Back $81.2M in STRC →
The potential fourth sweep signals that whoever is behind the incident may still be actively moving or consolidating stolen assets, a pattern that complicates recovery efforts and on-chain tracing for both victims and security researchers. Blockchain analytics firms and the broader crypto security community have been closely monitoring wallet addresses associated with the suspected drains.
For retail crypto holders, the incident underscores a persistent and uncomfortable truth: even air-gapped hardware wallets carry risk if seed phrases are compromised, stored digitally, or exposed during the initial setup process. Security experts consistently advise users to generate seeds in fully offline environments and never photograph or type recovery phrases into any internet-connected device.
The full scope of affected users and the definitive cause of the breach remained under investigation. Continue reading at CoinDesk.