Coinkite declines to size losses from Coldcard exploit
Security & Exploits ·
The maker of the Coldcard hardware wallet has not confirmed how much cryptocurrency was stolen through a software flaw exploited to drain user funds, with outside estimates now running to around $130 million.
Coinkite, which produces the Coldcard device, declined to speculate publicly on the scale of losses tied to the exploit, according to Bloomberg. The company has said it will publish a post-mortem once its investigation concludes, but has not set a timeline for that report. Separate figures circulating in the cluster place losses at more than $111 million, alongside the higher $130 million estimate, though no single confirmed total has been issued by Coinkite itself.
The incident centers on a software vulnerability rather than a physical compromise of the hardware wallet, meaning the offline storage model Coldcard is built around did not by itself prevent the theft. That distinction has drawn attention because hardware wallets are typically marketed as a safeguard against exactly this kind of loss, and the exploit suggests private key handling remains a weak point even when keys are kept off internet-connected devices.
Coverage of the exploit has framed private key management as a persistent structural risk in cryptocurrency custody, a point discussed in reporting from The Block, which also raises questions about AI-driven techniques as a factor in modern exploit development. Additional coverage of the episode has circulated through outlets including wublockchain.xyz, reflecting attention to the case beyond a single report.
Four distinct sources are tracking the story, according to the cluster of coverage, underscoring that the exploit and its fallout are being followed across multiple outlets even as core facts remain unsettled. What is not yet known is the exact amount stolen, the specific mechanism of the software flaw, and how many Coldcard users were affected.
Coinkite's promised post-mortem is expected to address the technical cause of the exploit and clarify total losses, but no publication date has been given. Until that report appears, the $130 million figure and the lower $111 million estimate stand as unconfirmed approximations rather than an official accounting from the company.