MultiversX Tracker is Live!

The Coldcard Hack: What Happened, What Actions to Take as a Coldcard Holder, and How U.S. Taxpayers May Claim Their Losses

All Cryptocurrencies

by COINS NEWS 15 Views

Last week's Coldcard hack was a huge blow to the Bitcoin self-custody community.

For years, self-custody has been viewed as the "responsible" and "safe" way to store Bitcoin, but this incident showed that even when you follow that advice, vulnerabilities can still exist, and in this case they allowed thieves to steal users' BTC.

What Happened?

On Thursday (July 30, 2026), Coldcard customers began reporting that their BTC was being sent out of their wallet without their authorization. What first appeared to be a few isolated incidents grew to impact over 7,000 wallets. Many of these wallets existed for years without previous issues or even transactions.

These transfers were the result of a vulnerability affecting the seed phrases that are generated when creating a Coldcard hardware wallet. Coldcard has released several generations of its hardware wallet over the years, including the Mk2, Mk3, Mk4, Mk5, and Q models. Wallets created on Mk2 and Mk3 devices using firmware versions 4.0.1 through 4.1.9 were the most vulnerable, although there were some Mk4, Mk5, and Q wallets also impacted.

When you create a new Bitcoin wallet, the device is supposed to generate a completely random seed phrase that only you know. Due to a bug in the firmware, some affected Coldcard devices didn't generate as much randomness as they should have. That made it possible for attackers (potentially with the help of AI) to mathematically figure out some users' private keys and steal the bitcoin stored in those wallets. If Coldcard users selected the "Roll Dice" option and generated their seed phrase using their own dice rolls instead of relying solely on the device's random number generator, they were not affected by this vulnerability.

What Actions to Take if Your Coldcard Wallet Wasn’t Hacked

If your bitcoin is still in your Coldcard wallet, now is the time to act. Simply updating the firmware is not enough if your wallet was created using an affected firmware version.

Here are the recommended steps:

  1. Determine whether your wallet is affected.
    • Mk2/Mk3: Firmware versions 4.0.1 through 4.1.9
    • Mk4/Mk5: Any wallet created before version 5.6.0 (Standard) or 6.6.0X (Edge)
    • Q: Any wallet created before version 1.5.0Q (Standard) or 6.6.0QX (Edge)
  2. Install the latest firmware. Update your Coldcard device to the latest firmware available for your model before generating a new wallet.
  3. Generate a brand new wallet. After updating, create a new seed phrase. Do not continue using your existing seed if it was generated on an affected firmware version.
  4. Verify the new wallet. Write down the new seed phrase, verify the wallet fingerprint and receive address, and confirm your backup is accurate.
  5. Move your bitcoin. Once you've confirmed everything is working properly, transfer your BTC to the new wallet.

What to Do if Your Coldcard Wallet Was Hacked

Bitcoin transactions are irreversible, and once the assets have been transferred to another wallet, recovery is extremely unlikely unless law enforcement identifies and seizes the stolen funds.

That said, there are still a few steps you should take:

1. Document everything. Save your wallet addresses, transaction IDs, firmware version, and any other information related to the theft.

2. File a report with the FBI's Internet Crime Complaint Center (IC3). While recovery is uncommon, reporting helps investigators identify larger patterns and may assist future enforcement actions. This report can be filed online in just a few minutes at https://www.ic3.gov/

3. Monitor your stolen funds. Blockchain explorers can help you track where your bitcoin moves, which may become useful if exchanges freeze or identify the assets in the future.

4. Consult a tax professional. Depending on your circumstances, you may be eligible to claim a theft loss deduction on your U.S. tax return.

U.S. Tax Implications

If you lost cryptocurrency due to a scam, hack, or theft, you may be able to qualify for an ordinary tax deduction under IRC Section 165(c)(2). The following qualifications generally must be met to claim the loss:

1. The loss must qualify as “theft” under the applicable state law. This means it includes a criminal act such as fraud, swindling, false pretenses, etc. The taxpayer must show the property was illegally taken and there was criminal intent.

2. The loss must arise from a profit-motivated transaction. The taxpayer purchased BTC and stored it in their cold wallet with the intent of making a profit.

3. The loss must be claimed in the tax year in which it was discovered, with no reasonable prospect of recovery at the end of that tax year.

#3 is the challenge with this hack, as the assets were stolen in 2026, but there is a chance that law enforcement may be able to recover the assets or that CoinKite may be found responsible and required to pay it’s customers. We will need to see how this situation evolves to determine whether there really is no reasonable prospect of recovery by the end of 2026.

Theft losses are reported on Section B of Form 4684, Casualties and Theft Losses, to the extent of the taxpayer’s COST BASIS. The cost basis part is important, as I often have to remind clients that even though the value of their crypto was much higher when it was stolen, they only get a deduction to the extent of their cost basis (price they paid).

From Form 4684, the resulting ordinary loss flows to Schedule A where itemized deductions are reported. It adds to the same deduction bucket where you report mortgage interest expenses, state taxes, etc.

Your total itemized deductions on Schedule A flow to your Form 1040 and reduce your taxable income.

To the extent the loss created is so big that you have a taxable loss for the tax year, the loss would be carried over and could be used to offset 80% of income in future tax years (IRC 172 limitations).

Note that many CPAs are hesitant to report a cryptocurrency theft loss. I believe this is largely due to confusion related to personal theft losses being nondeductible (per Tax Cuts and Jobs Act) or potentially just a lack of experience surrounding a substantial tax position. If your CPA is not comfortable taking the position, get a second opinion and consider speaking with a crypto-specialized CPA.

Conclusion

The Coldcard incident is a reminder that even the most trusted security tools can have vulnerabilities. While self-custody remains one of the best ways to protect your Bitcoin, no solution is completely risk-free. If you own a Coldcard wallet, take a few minutes to determine whether you're affected and migrate your funds if necessary. If you were one of the unfortunate victims, make sure to document everything, report the theft, and speak with a qualified tax professional to determine whether you're entitled to a deduction. Although nothing can replace stolen bitcoin, the tax code may at least help soften the financial impact.

submitted by /u/Garrett_CPAatCOS
[link] [comments]
Get BONUS $200 for FREE!

You can get bonuses upto $100 FREE BONUS when you:
💰 Install these recommended apps:
💲 SocialGood - 100% Crypto Back on Everyday Shopping
💲 xPortal - The DeFi For The Next Billion
💲 CryptoTab Browser - Lightweight, fast, and ready to mine!
💰 Register on these recommended exchanges:
🟡 Binance🟡 Bitfinex🟡 Bitmart🟡 Bittrex🟡 Bitget
🟡 CoinEx🟡 Crypto.com🟡 Gate.io🟡 Huobi🟡 Kucoin.



Comments