Coinkite hardware wallets exploited in $100M+ Bitcoin theft
A major security breach involving Coinkite's Coldcard hardware wallets has resulted in the theft of over $100 million in Bitcoin. The exploit, which unfolded in multiple waves starting around July 30, targeted users of several hardware models, including the Mk2, Mk3, Mk4, Mk5, and Q.
Investigations revealed that a software bug allowed attackers to reconstruct the
Entities: Bitcoin · Coinkite · Coldcard · Galaxy Research · TRM Labs · Toronto
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [○ 1 SOURCE] Hackers drained over $110 million in Bitcoin from approximately 5,000 to 7,300 wallets. (Galaxy Research)
- [○ 1 SOURCE] The exploit is the third-largest cryptocurrency hack of 2026. (TRM Labs)
- [○ 1 SOURCE] Products built on separate codebases, such as Tapsigner, Opendime, and Satscard, were not affected. (Coinkite)
- [○ 1 SOURCE] The vulnerability impacted several hardware models including Mk2, Mk3, Mk4, Mk5, and Q. (Coinkite)
- [● 2 SOURCES] A software bug allowed the reconstruction of seed phrases from hardware wallets. (Coinkite)
- [○ 1 SOURCE] The company has suspended its automated data erasure process due to legal obligations related to the theft. (Coinkite)