Unidentified hackers stole as much as $130 million [1] in Bitcoin from more than 7,300 cold-storage wallets [2] earlier this month.

The breach is significant because it undermines the perceived security of "cold storage," which is designed to keep cryptocurrency offline and safe from remote attacks.

The theft occurred in early August 2026 [3]. Attackers exploited a software bug in the firmware of Coldcard hardware wallets, which allowed them to bypass the offline security model and move funds from the devices [2, 3].

Estimates of the total loss vary across reports. The Motley Fool reported the stolen amount at $130 million [1], while Bitcoin Magazine estimated the loss at $111 million [4]. Forbes provided a lower estimate of $102 million [3]. Galaxy Research identified a total of 1,596 BTC [3] involved in the incident.

Victims of the exploit reported a median loss of one BTC [4]. The attack affected more than 7,300 wallets worldwide [2] that were managed using the Coldcard hardware.

Industry observers said the event highlights a critical vulnerability in hardware-based security. One report said that the incident "exposes the fallacy of your crypto being offline" [2].

Coldcard wallets were previously billed as secure options for long-term investors seeking to avoid the risks associated with online exchanges [2]. The discovery of a firmware bug that enables the unauthorized movement of funds suggests that even air-gapped systems can be compromised if the underlying software contains flaws.

It exposes the fallacy of your crypto being offline.

This breach challenges the fundamental trust in hardware wallets as the gold standard for cryptocurrency security. By exploiting firmware rather than network connectivity, hackers proved that 'cold' storage is not immune to remote-style vulnerabilities if the device's internal logic is flawed. This may lead investors to diversify their storage methods or demand more rigorous, third-party audits of hardware firmware.