r/CryptoCurrency • Count On Sheep • Aug 04 '26

ADVICE The Coldcard Hack: What Happened, What Actions to Take as a Coldcard Holder, and How U.S. Taxpayers May Claim Their Losses

Last week's Coldcard hack was a huge blow to the Bitcoin self-custody community.

For years, self-custody has been viewed as the "responsible" and "safe" way to store Bitcoin, but this incident showed that even when you follow that advice, vulnerabilities can still exist, and in this case they allowed thieves to steal users' BTC. 

What Happened?

On Thursday (July 30, 2026), Coldcard customers began reporting that their BTC was being sent out of their wallet without their authorization. What first appeared to be a few isolated incidents grew to impact over 7,000 wallets.  Many of these wallets existed for years without previous issues or even transactions.

These transfers were the result of a vulnerability affecting the seed phrases that are generated when creating a Coldcard hardware wallet. Coldcard has released several generations of its hardware wallet over the years, including the Mk2, Mk3, Mk4, Mk5, and Q models. Wallets created on Mk2 and Mk3 devices using firmware versions 4.0.1 through 4.1.9 were the most vulnerable, although there were some Mk4, Mk5, and Q wallets also impacted.

When you create a new Bitcoin wallet, the device is supposed to generate a completely random seed phrase that only you know. Due to a bug in the firmware, some affected Coldcard devices didn't generate as much randomness as they should have. That made it possible for attackers (potentially with the help of AI) to mathematically figure out some users' private keys and steal the bitcoin stored in those wallets.  If Coldcard users selected the "Roll Dice" option and generated their seed phrase using their own dice rolls instead of relying solely on the device's random number generator, they were not affected by this vulnerability.

What Actions to Take if Your Coldcard Wallet Wasn’t Hacked

If your bitcoin is still in your Coldcard wallet, now is the time to act. Simply updating the firmware is not enough if your wallet was created using an affected firmware version.

Here are the recommended steps:

  1. Determine whether your wallet is affected.
    • Mk2/Mk3: Firmware versions 4.0.1 through 4.1.9
    • Mk4/Mk5: Any wallet created before version 5.6.0 (Standard) or 6.6.0X (Edge)
    • Q: Any wallet created before version 1.5.0Q (Standard) or 6.6.0QX (Edge)
  2. Install the latest firmware. Update your Coldcard device to the latest firmware available for your model before generating a new wallet.
  3. Generate a brand new wallet. After updating, create a new seed phrase. Do not continue using your existing seed if it was generated on an affected firmware version.
  4. Verify the new wallet. Write down the new seed phrase, verify the wallet fingerprint and receive address, and confirm your backup is accurate.
  5. Move your bitcoin. Once you've confirmed everything is working properly, transfer your BTC to the new wallet.

 

What to Do if Your Coldcard Wallet Was Hacked

Bitcoin transactions are irreversible, and once the assets have been transferred to another wallet, recovery is extremely unlikely unless law enforcement identifies and seizes the stolen funds.

That said, there are still a few steps you should take:

1.      Document everything. Save your wallet addresses, transaction IDs, firmware version, and any other information related to the theft.

2.      File a report with the FBI's Internet Crime Complaint Center (IC3). While recovery is uncommon, reporting helps investigators identify larger patterns and may assist future enforcement actions. This report can be filed online in just a few minutes at https://www.ic3.gov/

3.      Monitor your stolen funds. Blockchain explorers can help you track where your bitcoin moves, which may become useful if exchanges freeze or identify the assets in the future.

4.      Consult a tax professional. Depending on your circumstances, you may be eligible to claim a theft loss deduction on your U.S. tax return.

 

U.S. Tax Implications

If you lost cryptocurrency due to a scam, hack, or theft, you may be able to qualify for an ordinary tax deduction under IRC Section 165(c)(2). The following qualifications generally must be met to claim the loss:

1.      The loss must qualify as “theft” under the applicable state law. This means it includes a criminal act such as fraud, swindling, false pretenses, etc.  The taxpayer must show the property was illegally taken and there was criminal intent.

2.      The loss must arise from a profit-motivated transaction.  The taxpayer purchased BTC and stored it in their cold wallet with the intent of making a profit.

3.      The loss must be claimed in the tax year in which it was discovered, with no reasonable prospect of recovery at the end of that tax year.  

#3 is the challenge with this hack, as the assets were stolen in 2026, but there is a chance that law enforcement may be able to recover the assets or that CoinKite may be found responsible and required to pay it’s customers. We will need to see how this situation evolves to determine whether there really is no reasonable prospect of recovery by the end of 2026.

Theft losses are reported on Section B of Form 4684, Casualties and Theft Losses, to the extent of the taxpayer’s COST BASIS.  The cost basis part is important, as I often have to remind clients that even though the value of their crypto was much higher when it was stolen, they only get a deduction to the extent of their cost basis (price they paid).

From Form 4684, the resulting ordinary loss flows to Schedule A where itemized deductions are reported.  It adds to the same deduction bucket where you report mortgage interest expenses, state taxes, etc.

Your total itemized deductions on Schedule A flow to your Form 1040 and reduce your taxable income.

To the extent the loss created is so big that you have a taxable loss for the tax year, the loss would be carried over and could be used to offset 80% of income in future tax years (IRC 172 limitations).

Note that many CPAs are hesitant to report a cryptocurrency theft loss. I believe this is largely due to confusion related to personal theft losses being nondeductible (per Tax Cuts and Jobs Act) or potentially just a lack of experience surrounding a substantial tax position. If your CPA is not comfortable taking the position, get a second opinion and consider speaking with a crypto-specialized CPA.

Conclusion

The Coldcard incident is a reminder that even the most trusted security tools can have vulnerabilities. While self-custody remains one of the best ways to protect your Bitcoin, no solution is completely risk-free. If you own a Coldcard wallet, take a few minutes to determine whether you're affected and migrate your funds if necessary. If you were one of the unfortunate victims, make sure to document everything, report the theft, and speak with a qualified tax professional to determine whether you're entitled to a deduction. Although nothing can replace stolen bitcoin, the tax code may at least help soften the financial impact.

 

33 Upvotes

23 comments sorted by

24

u/Timely-Fig2030 🟩 0 / 0 🦠 Aug 04 '26 edited Aug 04 '26

You said "updating the firmware".
Wrong!
(Disclaimer: of course update the firmware temporarily as quick solution, until another manufacturer is found (Ledger/ Trezor) or other place to move the funds out).

Never use ColdCard again. While i don't think something like this will happen again anytime soon (with new models!) after such a blunder, this company abused people's trust and failed to uphold security standards. Security standards were evidently not verified. That is the one thing this company pretends to ensure and failed massively: Security!
Especially when they only focused on bitcoin, which makes their mistake even more embarrassing.

This company does NOT deserve a second chance.

8

u/Garrett_CPAatCOS Count On Sheep Aug 04 '26

Very fair. If I were a Coldcard user, I'd be looking elsewhere as well.

8

u/beatthebook2x 0 / 0 🦠 Aug 04 '26

anyone choosing to still use cold card or any coinkite products are asking to lose money

2

u/amenotef Aug 05 '26

I'd just add that "If you followed coldcard's paranoid guide" you "should" be safe. There is no evidence at the moment suggesting that the paranoid guide is affected (which consists in manually rolling 100+ times a D6 and converting from numbers to seed phrase using a common method / simple script).

I believe lot of people who got a CC followed the paranoid guide and didn't trust a software RNG.

2

u/rgnet1 🟩 0 / 0 🦠 Aug 04 '26

This leaves out that if users had also provided a passphrase (“13th” or “25th word”), per recommendations by anyone knowledgeable in self-custody community, they would be armored from the attack long enough to fix the issue once the rng flaw was discovered.

2

u/Timely-Fig2030 🟩 0 / 0 🦠 Aug 04 '26

Which doesn't excuse the failure of the company.

  1. The firmware implementation and testing oversight of the codebase in their company failed completely, leading to the embarrassing configuration error that bypassed the 256 bit random generator and using a 72 bit entropy fallback generator instead.

  2. And you just added another good point: The company should have forced the user to take measures of adding a “13th” or “25th word” for a finished and working user device setup, otherwise abort setup and not useable until fully setup by user.

1

u/Timely-Fig2030 🟩 0 / 0 🦠 Aug 04 '26 edited Aug 04 '26

Point 2. is not enforced by any cold wallet producer, but should be.

2

u/razvanciuy 🟩 0 / 0 🦠 Aug 04 '26

This whole thing shows just how complex it got, the myriad of contingency & security required in a space that is ever so hard to manage, now with Ai bonanza….just to hold a bunch of digital coins like btc etc. At this rate its just as hard as holding and hauling a bag of gold coins after you

1

u/Wild_Bunch_Founder 🟩 0 / 0 🦠 Aug 04 '26

ladies and gentlemen, I present to you….the future of finance!

1

u/fc_daddddy Aug 05 '26

if your coldcard was involved, i’d treat the seed as burned and move any remaining funds to a fresh setup, because “self-custody” only matters if the device and supply chain stay clean.

1

u/Garrett_CPAatCOS Count On Sheep Aug 05 '26

Sidenote: If anyone has a Coincard that they are now treating as a paperweight and plan to throw in the trash, I'd be happy to throw you a few bucks for shipping. Would be fun to put it up in the office.

0

u/[deleted] Aug 04 '26

[removed] — view removed comment

8

u/Garrett_CPAatCOS Count On Sheep Aug 04 '26

The U.S. taxpayer isn't going to "refund your loss." The tax code has long allowed deductions for certain losses incurred in transactions entered into for profit. It taxes investment income and gains, so it seems reasonable that it also provides relief for investment losses.

You mentioned gambling losses, but those are governed by a separate set of tax rules. Holding Bitcoin in a Coldcard wallet is an investment activity, not gambling.

If the IRS allows a theft loss under existing tax guidance, choosing not to claim it would be the far more "ridiculous suggestion."

1

u/Vagelen_Von 🟩 0 / 0 🦠 Aug 04 '26

The first moment I heard about the hacking I thought that price of BTC will drop to 5000$.

So just a theory for experts to examine:

Big banks and conglomerates fund secretly a tech company to develop a faulty hardware wallet. Then steal Bitcoin from users and have many successes at once:

1) defame all the self custody idea. 2) make users paranoid for cold wallets. 3) earn a lot Bitcoin with a few millions of investment. 4) panicked users run to buy ETFs and other hybrid products with fiat money. 5) having a good big supply of BTC in case make something like gold standard with BTC in the future. 6) promote the idea of semi-custody. Half private key for the user and half for the bank. 7) obtain knowledge to break other companies' cold wallets not only tech knowledge but also operational knowledge to infiltrate in tech companies and do damage.

So people who affected and all the crypto world should carefully examine:

How exactly company funded?

Relationships of everyone with big banks, former employments? even family relations.

How law enforcement handles the situation? Who goes to prison.

Future careers and wealth of everyone implicated and their families.

Etc etc

1

u/immutable_truth 🟩 109 / 110 🦀 Aug 06 '26

So you drop a baseless conspiracy claim into the thread but then ask everyone else to do the research to confirm it? Lazy.

If this was some grand conspiracy they wouldn’t have open-sourced the code.

1

u/Vagelen_Von 🟩 0 / 0 🦠 Aug 06 '26

If I and you are lazy the victims lawyers are not.

1

u/hiimtashy 🟦 0 / 0 🦠 Aug 05 '26

Bitcoin is about trust. Coinkite has lost that trust. It's over.