The hack, which targeted users of Coldcard — a popular hardware wallet made by Coinkite — has emerged as one of the larger cryptocurrency theft incidents of 2026. Galaxy Research’s tally, published Monday, provides the most detailed public accounting of losses so far. The report states that of the 221 confirmed victim reports, a “significant majority” reported losses exceeding 1 BTC, though the precise distribution was not disclosed.
Coldcard wallets are widely used by Bitcoin maximalists and security-conscious investors because of their air-gapped design and open-source firmware. However, the breach appears to have exploited vulnerabilities in the supply chain or firmware update process, though Coinkite has not issued a public forensic report as of press time. Galaxy Research’s numbers suggest that the attackers managed to compromise wallets across multiple batches, potentially through a targeted seed-phrase interception or a malicious firmware upgrade.
The fact that 87% of the stolen Bitcoin — worth roughly $115 million at current prices — has not been moved has led analysts to believe the attackers may be holding out in hopes of avoiding detection, or that they were unable to immediately liquidate such large sums. Alternatively, the funds could be stored in cold storage by the hackers themselves, waiting for a favorable market or better laundering opportunities.
Victims have taken to social media to express frustration, with some claiming that Coinkite’s response has been slow. Coinkite representatives have not commented on Galaxy’s findings but have previously stated that they are cooperating with law enforcement. The incident has reignited debate about the security of hardware wallets, which are often promoted as the safest method for storing cryptocurrency.
The crypto community is watching for further updates, particularly any movement from the unidentified wallets holding the bulk of the stolen funds. Galaxy Research noted that it will continue monitoring the situation.