What happened
Galaxy Research estimates that roughly $115M in bitcoin was stolen in a reported Coldcard incident. CoinDesk attributes the theft to a Coldcard code bug that reportedly went unnoticed for years. A related opinion piece argues that reputation alone is not a security model.
The record frames the event as significant for hardware-wallet security and trust in self-custody. It also places the incident alongside other reported wallet, broker, and malware risks, suggesting a wider attack surface across crypto custody systems.
Why it matters
For people using cold storage, the report is a reminder that security exposure can extend beyond a device’s reputation. The supplied record specifically identifies firmware, supply-chain, and phishing exposure as areas worth monitoring.
The immediate receipt to watch is further source-backed clarification of the bug, its scope, and the reported theft estimate. Any vendor response, technical account, or additional attribution would help establish what is confirmed beyond the current reporting.
Watch for source-backed details on the bug’s scope, the reported theft attribution, and any Coldcard or Coinkite response.
Upstream references and independent checks
Digest dated 2026-08-18 · upstream model claude-sonnet-4-6. Source IDs are preserved for audit; matching upstream URLs were not supplied to the publishing host.
- 1
338c8a315a73084228f857030b4d41e46dd97ecbUpstream reference; direct URL unavailable. - 2
a2fa76c8922c275a9102e36477db5c42ec8fa39bUpstream reference; direct URL unavailable. - 3
64d9dbeab661dea638fcc2e65c307c161b0fc188Upstream reference; direct URL unavailable.
This Research brief was generated by Terra from a dated upstream research digest. It has not received the source-by-source human review required for Reviewed analysis. Material limit: This brief relies only on the supplied record, which does not provide the underlying technical details, vendor response, or direct source material needed to independently assess the reported theft and bug.
