More than 1,000 Bitcoin wallets have been confirmed compromised in the Coldcard hardware-wallet incident, with losses now estimated at $71 million, roughly double the figure cited in early reporting on the breach.
Why it matters
Coldcard markets itself to the high-security end of the Bitcoin custody stack, including air-gapped signing, multisig workflows and a reputation among long-term holders. A supply-chain compromise that hits 1,000+ wallets at once reframes a niche hardware failure as a custody-class risk. If the malicious firmware reached devices through a genuine vendor channel rather than user-side phishing, the trust boundary shifts from "did the user get tricked" to "did the device ship compromised," and that is the question every institutional cold-storage team is now reviewing.
Market impact
Bitcoin's price has not shown a measurable reaction on the headline, which is consistent with how supply-chain incidents in this segment have priced in historically: impact concentrates in the affected vendor, competitors offering migration paths, and the broader perception of self-custody risk premium. Watch for firmware guidance from Coldcard, wallet-migration announcements from competitors, and any follow-up attribution that clarifies whether the breach crossed into retail devices or stayed inside a specific batch or distribution channel.
Frequently asked questions
-
How many Bitcoin wallets were affected in the Coldcard incident?
More than 1,000 wallets were confirmed compromised, with losses now estimated at $71 million, roughly double the figure cited in early reporting on the breach.
-
Why is the Coldcard breach described as a supply-chain attack?
The framing follows from the scale and reach of the compromise. If malicious firmware reached devices through a genuine Coldcard distribution channel rather than user-side phishing or tampered imports, the trust boundary shifts from the holder's behavior to the device's factory state.
-
How has Bitcoin's price reacted to the Coldcard news?
Bitcoin has not shown a measurable price reaction on the headline, consistent with how supply-chain incidents in this segment have historically priced in. Impact concentrates in the vendor and competitors rather than spot price.
-
Who is most at risk from this Coldcard compromise?
Holders using affected Coldcard devices for self-custody, including long-term holders and small institutional desks that prioritized Coldcard for air-gapped signing and multisig workflows. The risk scales with how widely a compromised firmware version was distributed.
-
What should affected Coldcard users do now?
Watch for official firmware guidance and wallet-migration instructions from Coldcard. Until attribution clarifies whether the breach was confined to a specific batch or distribution channel, moving funds to a clean device or to a non-Coldcard signer is the conservative move.
CoinTelegraph