That’s according to Galaxy Research, which posted those calculations on X Sunday (Aug. 16), saying they were based on its data through Aug. 13.
The company added it has spoken with more than 200 victims “to support them and gather intelligence on the attackers.”
The incident happened when attackers exploited a vulnerability affecting older versions of firmware used by Coldcard, a popular bitcoin hardware wallet made by Coinkite. The five-year-old flaw went undetected until it was too late, weakening the randomness used to create some wallets’ recovery phrases, making it easier to discover the private keys derived from them and drain Bitcoin from thousands of users.
Meanwhile, Twenty-One Million, a company that provides crypto-related trackers and calculation tools, has established a page designed to stay current as the incident evolves. It notes that some trackers place losses at more than $130 million. Both Coinkite itself and TRM Labs have created their own pages to provide updates on the theft.
“This is one of the largest hardware-wallet failures in Bitcoin’s history, and coverage broadly describes it as one of the largest single crypto thefts of 2026,” Twenty-One Million said.
The company also notes that “weak randomness” has targeted bitcoin wallets in the past, with incidents like the 2023 “Milk Sad” bug and the 2022 Wintermute hack both instances of “predictable randomness that looked identical to real randomness until someone checked.”
“That’s a real point in favor of open-source, auditable hardware — bugs like this are eventually findable in public code — but it’s also a reminder that ‘open source’ catches problems eventually, not instantly, and doesn’t substitute for the extra protections (dice rolls, a passphrase, real multisig) described above,” the company said.
Meanwhile, PYMNTS wrote earlier this month that the Coldcard failure highlights the risk of treating offline storage as the final word in the security discussion.
“A device disconnected from the internet can still generate a vulnerable key. Open-source software can still contain a flaw,” that report said. “Assets can still disappear without the device ever leaving a safe.”
It’s what makes the Coldcard crypto incident important for institutional custody, demonstrating that the most critical security questions are outside the blockchain and in the hardware, software, governance and operational controls determining who can provide a valid signature.
The wallet incident is part of a larger series of crypto-related thefts this year, with losses reaching around $972 million for the first seven months of 2026, per a recent CoinDesk report.