The ongoing theft targeting Coldcard hardware wallet users has escalated substantially, with cumulative losses now exceeding $114 million worth of Bitcoin. According to Bitcoin Magazine, the exploit remains active, and victims continue to report drained wallets as the attack persists without interruption.

The scale of the theft marks a significant milestone in hardware wallet security incidents, demonstrating that even devices designed to provide offline, cold storage solutions remain vulnerable to sophisticated exploitation. While hardware wallets typically isolate private keys from internet-connected devices to prevent remote attacks, the current Coldcard situation illustrates persistent vulnerabilities that have allowed attackers to systematically extract funds over an extended period.

Bitcoin Magazine reports that the drain is ongoing, indicating that wallets continue to be emptied as the exploit progresses. This sustained nature of the theft distinguishes it from isolated security breaches. The continuous outflow of funds implies that new victims are still being identified or that previously compromised wallets are being liquidated methodically, though the specific mechanism enabling the ongoing unauthorized access remains unspecified in current reporting.

The $114 million figure represents a substantial concentration of Bitcoin wealth now controlled by malicious actors. In the context of cryptocurrency security, such losses underscore the evolving threat landscape facing self-custody solutions. Hardware wallets like Coldcard are generally considered the gold standard for securing significant Bitcoin holdings, relying on air-gapped signing and specialized secure elements to protect against remote extraction of keys. The magnitude of this particular incident challenges prevailing assumptions about the invulnerability of offline storage systems when faced with persistent, sophisticated attacks.

The persistence of this exploit raises critical questions about the security assumptions underlying current hardware wallet architectures. When devices marketed for their robust security characteristics suffer nine-figure losses through ongoing theft, users must reassess their threat models, including the integrity of firmware updates, physical device handling, and seed phrase generation environments. The fact that the theft continues suggests that the root cause remains unaddressed or that the attacker maintains persistent access to a significant number of compromised devices or keys. This sustained campaign indicates a level of access and organization that extends beyond typical opportunistic cryptocurrency theft.

As the total stolen amount surpasses $114 million, the incident serves as a stark reminder that no storage solution offers absolute protection against determined adversaries. Users holding Bitcoin in Coldcard devices must remain vigilant, monitoring for official security advisories and considering additional operational security measures until the exploit vector is definitively identified and patched. The ongoing nature of the drain indicates that the window for securing remaining vulnerable funds may still be open, but closing rapidly as attackers continue their systematic extraction of assets from affected wallets.