What happened
CoinTelegraph reported Tuesday that investigators tracing the Coldcard hack have not landed on a definitive loss figure, and are unlikely to for several more days. The probe is running on two parallel tracks. One relies on victims coming forward and reporting drained balances directly, which produces a floor number that undercounts anyone who has not yet noticed or gone public. The other tracks stolen coins on-chain, clustering addresses tied to the theft and following the outflows as they move. The two numbers rarely match in the first 48 hours of any breach, and this one is no exception.
Coldcard, built by Coinkite, is an air-gapped Bitcoin hardware wallet popular with self-custody purists and long-term holders. That user profile matters. Coldcards tend to sit on balances that have not moved in months or years, which means the on-chain tracers are watching dormant UTXOs suddenly light up and travel in patterns that look nothing like normal wallet activity. Coinkite has not published a full incident summary as of Tuesday morning, and the initial reporting does not attribute the compromise to a specific vector - firmware, supply chain, seed extraction, or user-side phishing all remain on the table.
Why it matters
Hardware wallets are the load-bearing wall of retail self-custody. When one of the trusted names takes a hit, the confidence hit spreads well beyond the specific device. Coldcard's whole pitch is that it's the paranoid option, the one you use when you don't trust anything else, so any breach that touches it forces a re-underwriting of the entire cold storage stack for a slice of the market that specifically opted out of exchanges and multisig custodians.
