What happened
Bitcoin Magazine reported Monday that Bitcoin stolen from users of Coinkite's Coldcard hardware wallet has crossed $114 million, with fresh drains continuing to hit wallets over the weekend. The report, written by Mathew Di Salvo, describes an active theft campaign rather than a one-off breach, with balances disappearing from addresses tied to the device across multiple days. Coldcard is a signer-only, air-gapped hardware wallet made by Canadian firm Coinkite, and it has been one of the most cited devices in Bitcoin self-custody circles for years.
That reputation is what makes the running tally uncomfortable. As of Monday afternoon, neither the initial vector nor the identity of the attackers has been publicly confirmed, per Bitcoin Magazine's reporting.
Why it matters
Hardware wallets are the layer most self-custodial Bitcoin holders rely on to sleep at night. A $114 million loss traced to users of a single, security-first device is a stress test of that assumption. Coldcard sits in the same bucket in the retail mind as Ledger and Trezor, which means the fallout won't stay inside Coinkite's customer base.
Every serious Bitcoin holder using cold storage is now doing the same mental math: is my seed phrase safe, is my firmware clean, did I buy from an authorised reseller. The headline looks like a Coldcard story. The read-through is a self-custody story.
Market impact
Bitcoin Magazine's report does not name specific addresses, exchanges, or coin flows in the excerpt available, and no affected-coin price feed accompanied the release. The market impact so far is reputational rather than mechanical, hitting confidence in the self-custody stack rather than triggering a visible spot dislocation. Hardware wallet incidents of this size historically pull two things forward.
