A firmware defect in Coldcard hardware wallets has been exploited, draining an estimated $130 million in Bitcoin from users—at least 1,596 BTC confirmed on-chain, with blockchain monitoring firms flagging additional outflows still in motion.

This is not a phishing attack or seed phrase leak. The exploit hit at the device level, targeting a specific firmware vulnerability before users ever touched their keys. That distinction matters: it means doing everything right was not enough.

Coinkite, the Toronto-based manufacturer behind Coldcard, said it cannot confirm the $130 million figure. The company collects no customer data by design, so it has no independent mechanism to tally aggregate losses. That same privacy architecture that makes Coldcard attractive to serious Bitcoiners is now the reason there is no official damage report.

Outside blockchain analytics firms are filling the gap. Multiple monitoring operations have independently tracked outflows surpassing $100 million, with the running total approaching $130 million as activity continues.

Coinkite is preparing a technical post-mortem that will detail the firmware flaw and its exploitation method. Until that document drops, users should watch official Coinkite channels and treat any third-party loss estimates as lower bounds, not final figures.

Bitcoin trades at $65,237, up 1.3 percent over the past 24 hours. Ethereum is at $1,931, up 1.7 percent.

For anyone holding Bitcoin in self-custody right now, the core question is whether your firmware is current and whether your device was manufactured within the affected production window. Coinkite has not yet specified which firmware versions are compromised—that is the critical disclosure still pending in the post-mortem.

This breach will pressure the entire hardware wallet sector to tighten firmware audit cycles and accelerate public defect disclosure. Self-custody is still the right call. But device-level security is no longer an afterthought.