A security breach targeting Coldcard hardware wallets produced by Coinkite has drained millions of dollars in Bitcoin from thousands of users [1, 2].

The exploit challenges the perceived safety of self-custody, the practice of holding private keys offline to avoid exchange hacks. As users lose confidence in hardware wallets, the incident may accelerate a shift toward institutional custody solutions.

Estimates of the total stolen funds vary across reports. Some analysts estimate the total loss at $130 million [1], while other observations recorded losses of roughly $88.6 million following a third wave of thefts [5]. The breach affected approximately 7,300 wallet addresses [1].

Individual losses have been severe. One Canadian user reported losing $1.6 million within minutes [3]. Despite the scale of the theft, some analysts suggest the probability of recovering the stolen Bitcoin is low, estimated between 20% and 40% [6].

Alex Thorn, head of firmwide research at Galaxy Digital, said Bitcoin will survive the incident [1]. The vulnerability resided in the Coldcard software, which attackers exploited to siphon funds for profit [1, 4].

Market data suggests some investors are moving funds toward regulated entities in response to the breach. U.S. spot Bitcoin ETFs saw inflows of $382 million over two days following the news [2]. This trend indicates a growing preference for managed custody over individual hardware ownership during periods of high volatility or security failures.

The attack occurred in August 2026, targeting globally distributed wallets [4]. Coinkite has not provided a definitive timeline for full recovery of the assets, though the nature of the blockchain makes unauthorized transfers nearly impossible to reverse without the attackers' cooperation.

The breach affected approximately 7,300 wallet addresses.

This breach underscores a critical tension in the cryptocurrency ecosystem between the ideology of 'not your keys, not your coins' and the practical security risks of self-management. While hardware wallets are designed to be the gold standard of security, a software-level vulnerability can render physical isolation moot. The immediate pivot toward U.S. spot ETFs suggests that institutional-grade custody may become the default for high-net-worth investors who cannot afford the total loss associated with a single point of failure in consumer hardware.