Coldcard hack — why nobody agrees on how much Bitcoin was stolen
Investigators still cannot agree on how much Bitcoin was drained in the recent Coldcard hack, with estimates ranging fro…
Investigators still cannot agree on how much Bitcoin was drained in the recent Coldcard hack, with estimates ranging from about 1,432 BTC to more than 1,800 BTC, because the stolen coins sat in self-custody wallets rather than on an exchange.
When an exchange is hacked, the company knows exactly which accounts were touched. Self-custody is different: there is no central list of victims, so investigators have to build estimates from the reports people volunteer and from patterns they can trace on the blockchain.
That is why the numbers diverge. Blockchain analytics firm CryptoQuant takes the strictest approach and confirms 1,432 BTC, treating it as a floor that could rise as more victims come forward. Galaxy Research puts its high-confidence minimum at 1,730 BTC — it has directly confirmed more than 450 BTC from victim reports and used those to identify over 730 BTC in total, while an earlier figure of as much as 1,816 BTC was only a potential estimate. TRM Labs independently traced roughly 1,816 BTC drained from more than 5,200 addresses across four waves.
Analysts warn the tally will keep moving and may never be exact. CryptoQuant says it avoids naming victims purely from on-chain patterns because that risks false positives that inflate the total, and its head of research stressed the figure will always be an estimation. Chainalysis has not done its own count, and investigator ZachXBT said he has no plans to trace the incident.
For a beginner, the lesson is not that self-custody is bad, but that it comes with responsibility. Holding your own keys means there is no company to file a claim with and no complete record if something goes wrong — so keep wallet software and firmware current, verify what you sign, and treat official project channels as the only source of security instructions. This is information, not advice.