In brief
- The Coldcard firmware exploit drained approximately 2,100 BTC, with losses estimated near $130 million across multiple attack waves.
- Onchain data from Checkonchain shows 233,000 BTC left long-term holder wallets in the days around the breach.
- Casa CEO Nick Neuman, citing actual customer conversations, says some of that 233,000 BTC came from Ledger and Trezor users—not Coldcard owners—who upgraded to multisig after watching the hack unfold.
In the days after the worst hardware wallet exploit in Bitcoin’s recent history, Casa CEO Nick Neuman began counting more than just the BTC being drained from vulnerable Coldcard wallets.
While attackers were draining Coldcard wallets one address at a time, 233,000 BTC—worth about $15 billion at today’s prices—was quietly moving in search of safety.

The massive and ongoing breach that started on July 30 has already led to close to $130 million in stolen Bitcoin from Coldcard hardware wallets—physical gadgets that store private keys entirely offline, never connecting to the internet, and made by Canadian company Coinkite.
A firmware bug introduced in March 2021 had routed key generation through a weak software random number generator instead of the device's dedicated hardware chip. Private keys (the secret codes that prove ownership of Bitcoin and authorize any transaction) became guessable, with security collapsing from 128 bits to roughly 40—the cryptographic equivalent of a bank vault that turns out to have a four-digit PIN.




