Crypto hacks are not new, and 2026 has already been an expensive year for them. CertiK's Hack3D report counted more than $1.3 billion stolen across on-chain incidents in the first half of the year alone. Wallet and key compromises overtook smart-contract bugs as the costliest attack vector. The ColdCard exploit fits that pattern, except the target this time wasn't an exchange or a bridge. It was the hardware wallet millions of Bitcoin holders trust specifically because it keeps their keys offline.
Since July 30, 2026, attackers have drained more than $70 million in Bitcoin from ColdCard wallets, and the total has kept climbing as forensic tracing turns up more affected addresses. If some of that Bitcoin was yours, or you're holding a ColdCard and wondering whether you're exposed, the tax question sitting behind the headlines is not abstract. Here's what actually happened, why it happened, and what current US tax law says about whether a stolen-crypto loss like this one is deductible.
Key Takeaways
- The loss started at $38 million and kept growing: forensic tracing pushed the first wave alone to roughly $70 million, and the cumulative total across all waves reached close to $89 million by early August.
- The flaw was in the firmware, not Bitcoin: a five-year-old bug caused affected devices to generate wallet seeds with far less randomness than intended, not a break in Bitcoin's own cryptography.
- You don't owe tax on the theft itself: losing access to stolen Bitcoin isn't a disposal, so it creates no taxable event on its own.
- Deductibility depends on why you held the Bitcoin: personal-use losses follow the disaster-only casualty-loss rule, while Bitcoin held for investment or trading may still qualify for a separate theft-loss deduction.
- Documentation matters regardless of the outcome: proving what you held, and when you lost access to it, is what protects you no matter which way the deduction question lands.
What Happened: The ColdCard Exploit, Wave by Wave
ColdCard is a Bitcoin hardware wallet made by the Canadian manufacturer Coinkite, built for people who want their private keys generated and stored entirely offline. That offline design is the entire selling point of a hardware wallet, which is what made a bug inside the device's own seed-generation process so damaging.
Wave one: an estimate that kept revising upward
The first wave hit on July 30, 2026. An attacker drained roughly 594 BTC from about 500 wallets in around 25 minutes, and early reporting put the damage near $38 million. As forensic tracing identified more affected addresses tied to the same wave, that estimate grew to roughly 1,083 BTC, worth about $70 million, across 1,196 addresses drained over a fuller window of about 41 minutes.
Additional waves push the total toward $89 million
The first wave wasn't the last one. By August 2, 2026, tracing from the analytics firm Galaxy Research put cumulative losses across all waves at roughly 1,367 BTC, worth about $88.6 million, spread across 4,585 addresses. Galaxy Research cautioned that later waves may involve different attackers than the first, not necessarily a single actor working through the same list of addresses.
| Milestone | Date (2026) | Amount | Detail |
|---|---|---|---|
| First reports | July 30 | ~$38M (594 BTC) | ~500 wallets drained within roughly 25 minutes |
| Wave one, revised | July 30-31 | ~$70M (1,083 BTC) | Same wave, 1,196 addresses drained over roughly 41 minutes, as forensic tracing expanded |
| Cumulative, all waves | August 2 | ~$88.6M (1,367 BTC) | 4,585 addresses across multiple waves, per Galaxy Research |
The takeaway isn't that any single number was wrong. It's that the scope of the exploit kept expanding as investigators traced more affected addresses, the same reason the widely cited figure moved from the tens of millions to nearly $90 million within a few days.
Know exactly what you held, and when
If a ColdCard you used was affected, CoinTracking shows you precisely what was in that wallet before the exploit, timestamped and ready to back up your records.
Why This Happened: A Firmware Bug in the Random Number Generator
A hardware wallet's entire security model rests on one thing: the randomness used to generate its seed, the master key that everything else derives from. ColdCard devices are built with a dedicated hardware random number generator for exactly this reason, so that seed generation never depends on software alone.
According to Coinkite's own technical postmortem, a firmware regression traced back to March 2021 caused affected devices to rely on a software-based random number source instead of routing seed generation through that dedicated hardware component. Coinkite's own account, independently corroborated by security researchers at Block and at the Bitcoin security firm Wizardsardine, traces the regression to a safeguard in the firmware's build configuration that checked whether a flag existed rather than whether it was actually enabled. That distinction let the software fallback pass silently for years without anyone noticing.
The practical effect was a sharp drop in entropy, the actual randomness behind a generated seed. Coinkite's own estimate puts the effective entropy at roughly 40 bits on Mk2 and Mk3 devices and about 72 bits on Mk4, Mk5, and Q devices, both far short of the 128 bits the design called for. Lower entropy means fewer possible seeds to search through, which is what made it mathematically feasible for an attacker to reconstruct affected private keys without ever touching the physical device.
Coinkite issued a security advisory on July 30, 2026, and shipped patched firmware for every affected model by the following day. The company halted shipments of new units and said it destroyed remaining inventory that still carried the affected firmware. Patching alone does not fix an already-compromised seed. Affected users still need to generate a new seed on updated firmware and move their funds across.
Coinkite has published a detailed account of the root cause, but its own entropy estimates remain labeled preliminary, and a fuller formal review is still pending. Treat the mechanism described here as the best current understanding, not a fully closed investigation.
Do You Owe Tax on Bitcoin That Was Stolen From Your Wallet?
You don't owe tax on the theft itself. Having Bitcoin stolen from your wallet isn't a taxable event the way a sale or a trade is, because you never disposed of the asset by choice. The IRS's own digital asset guidance centers on selling, exchanging, or receiving digital assets, not on assets that were simply taken from you. If your ColdCard funds moved without your instruction, that specific loss event creates no reporting obligation on its own.
Two situations can still leave you with a real tax bill regardless of the theft. If you had already recognized gains on an earlier trade before the exploit happened, that income was taxable when you received it and stays taxable no matter what happened to the coins afterward. Separately, if Coinkite or a recovery effort eventually compensates affected users, whether in funds, in a settlement, or through some other process, that compensation may need its own tax evaluation depending on how it's structured. No compensation program had been announced as of this article's publish date, so treat this as something to revisit if and when one materializes.
Can You Deduct a ColdCard Hack Loss on Your Taxes? What Current Law Says
This is the harder question, and the answer depends on why you were holding the Bitcoin that got stolen. If you held it purely for personal use, the loss falls under the same rule as any other personal casualty loss: a deduction is generally not allowed unless the loss was caused by a federally or state-declared disaster, and a firmware exploit doesn't meet that bar.
That restriction isn't temporary. The IRS confirms that recent legislation made the disaster-only requirement permanent, rather than letting it expire and revert to the broader, pre-2018 rules. Starting with the 2026 tax year, the same update also expanded which disasters qualify, adding certain state-declared disasters alongside federally declared ones. Either way, an anonymous firmware exploit on a hardware wallet doesn't qualify as a declared disaster under either version of the rule.
Most people who bought a dedicated hardware wallet to hold Bitcoin, rather than to spend it directly, are holding that Bitcoin as an investment, and that puts them in a different category. A theft loss on crypto held for investment or profit can still be deductible, disaster or no disaster. A 2025 IRS Office of Chief Counsel memorandum on scam and hack victims confirms this path stays open. Three conditions generally apply: the loss must qualify as theft under state law, you need a genuine profit motive behind holding the asset, and you must have no reasonable prospect of recovering the funds. Form 4684 (Casualties and Thefts) reflects the same split: Section A covers personal-use property and is gated by the disaster requirement above, while Section B covers investment and income-producing property and carries no disaster requirement at all.
A narrow safe harbor also exists for certain investment theft losses tied to a fraudulent arrangement with an identified, indicted lead figure, think Ponzi-scheme cases. Whether that narrower provision could ever apply to an anonymous firmware exploit with no identified perpetrator is a different and much less certain question, and it's not something to assume applies here.
Which category your own loss falls into, personal-use or investment-motivated, is something only a tax professional can determine for your specific situation. It shouldn't be assumed either way. This is the same framing CoinTracking has used for other exchange failures and hacks, including crypto losses from the FTX bankruptcy and the BlockFi bankruptcy. What changes the calculation for a lot of ColdCard users is the investment-motive path above, which is why the answer here isn't a flat no.
Outside the US, the rules differ by jurisdiction. Australia's Tax Office, for instance, publishes its own guidance for loss or theft of crypto assets, worth checking if you file outside the US.
How to Document a Hardware Wallet Theft for Your Taxes
If the loss itself turns out not to be deductible for you, documenting it still matters. Good documentation protects you from a different problem: being unable to prove what you actually held, when you lost access to it, and what your cost basis was on everything that came before and after. That protects the accuracy of your remaining holdings and gives you something concrete if the rules around theft losses change again, or if a compensation process eventually opens up.
The mechanics look a lot like building a Source of Funds report. Instead of proving where money came from, you're proving what you had, at what point in time, and what happened to it next. A few things are worth pulling together immediately, before records get harder to find.
- Wallet balance: a timestamped screenshot or export showing exactly what your ColdCard held immediately before the exploit.
- Transaction history and cost basis: the acquisition dates and cost basis of the specific coins that were in that wallet, calculated the same way as any other taxable event, typically using FIFO or another accounting method.
- The official advisories: save your own copy of Coinkite's security advisory and your device's firmware version history, since official pages can be edited or taken down as an investigation continues.
- Any correspondence about compensation: if a recovery process or compensation program opens up later, keep every message and date.
- A clear timeline: when you set up your seed, when the exploit happened, and when, if ever, you learned about it.
A CoinTracking import does most of this automatically for anything already connected to your account. Every trade, deposit, and transfer carries its own timestamp and cost basis. If a wallet you use is ever caught up in a future incident, you already have the record instead of reconstructing it from memory.
Document the loss properly
CoinTracking imports your transaction history from over 400 exchanges and wallets and generates a Source of Funds report that traces exactly where your crypto came from and where it went, gaps included.
What This Means for You: Three Scenarios
Where you stand depends on your own situation, not just on the headline dollar figure. Most readers will fall into one of three cases: a ColdCard address that was actually swept, a ColdCard that hasn't been affected yet, or a different hardware wallet entirely that this story has you rethinking.
Scenario A: Your ColdCard address was swept
Save everything listed above now, while Coinkite's advisories and your own records are still easy to find. Check Coinkite's official channels for updates rather than third-party rumors, and don't assume a deduction is available before speaking with a tax professional. Documentation is what protects you either way.
Scenario B: You own an affected ColdCard, but weren't hit yet
Update to patched firmware and generate a brand-new seed immediately, then move your funds across using a small test transaction first. Being unaffected so far doesn't mean your existing seed is safe if it was generated on vulnerable firmware; it likely means an attacker simply hasn't gotten to your address yet.
Scenario C: You use a different hardware wallet
This exploit is a reminder that self-custody shifts risk rather than removing it. A hardware wallet protects you from an exchange collapsing, but it's still only as secure as its own firmware, which is precisely what failed here. Keeping your own transaction history and cost basis current, independent of any single wallet or device, is what actually protects you if a similar flaw ever surfaces somewhere else.
"A hardware wallet is supposed to be the safest place to hold Bitcoin, which is exactly why this exploit landed so hard. It doesn't change what you need to prove for tax purposes though. You still need your own record of what you held, when you lost access to it, and what your cost basis was, regardless of which device generated the seed in the first place."
Luis Schilli, Head of Marketing at CoinTracking
Conclusion
The tax answer isn't a flat no: it depends on why you held the Bitcoin, personal use or investment, not on a blanket rule for hardware wallet hacks. The exploit itself came down to a firmware bug that starved seed generation of real randomness, not a flaw in Bitcoin itself, and the dollar total kept climbing as tracing expanded, from an initial $38 million estimate to nearly $89 million within days. Documentation is what you control either way: save your balance, your cost basis, and Coinkite's own advisories now, and you're ready whichever way the deduction question lands.
Keep your records ready for whatever comes next
CoinTracking has tracked crypto portfolios and calculated taxes for over 2.2 million users since 2012, across more than 400 exchanges and wallets. Import your history once, and you're ready the next time a wallet, exchange, or protocol has a bad week.
Disclaimer
The information in this article reflects publicly available reporting as of August 3, 2026. Coinkite's technical account of the root cause remains labeled preliminary as of this publish date, and dollar figures may continue to change as investigations proceed and additional affected addresses are identified. This article is for general informational purposes only and does not constitute financial, tax, or legal advice. Tax treatment of stolen or hacked cryptocurrency depends on your individual circumstances and on current law, which can change. Readers should consult a qualified tax professional before making decisions based on the information presented here. The author and publisher are not responsible for any losses or damages incurred as a result of using the information in this article.