Cryptocurrency theft across all attack vectors totaled $1.2 billion in 2026 through 276 separate incidents, according to analysis by TRM Labs. A single exploit of Coldcard hardware wallets accounted for $116 million of that total, or roughly 10 percent of year-to-date losses.
The Coldcard breach stands as the largest hardware wallet exploit on record. TRM Labs traced the attack to a vulnerability in Coldcard devices manufactured by Coinkite, which allowed attackers to extract private keys from affected units. Hardware wallets are designed to store cryptocurrency keys offline and are considered among the most secure storage methods available to retail and institutional holders.

The $1.2 billion aggregate figure covers 276 separate incidents. TRM Labs compiles its figures from on-chain transaction analysis, law enforcement filings, and direct victim reports. The incidents span categories ranging from exchange breaches and smart contract exploits to phishing attacks and physical theft of hardware devices.

Coldcard devices ship with a security model that holds keys offline in a dedicated processor, isolating them from internet-connected systems. The vulnerability TRM Labs documented allowed attackers who gained physical access to affected units to bypass this isolation through a side-channel attack on the device's firmware. Coinkite has not disclosed how many units were affected overall, only that the vulnerability existed in certain production batches manufactured before a firmware update released in early August.
For years, the majority of crypto theft occurred through centralized exchange breaches and smart contract bugs. Attackers are now targeting individual wallets that hold larger balances, a category that includes long-term holders and institutional custodians who moved assets to self-custody specifically to avoid exchange risk.
TRM Labs' August analysis named Coldcard as responsible for more theft in a single event than any other attack category recorded in 2026 to date. The prior largest single incident involved a cross-chain bridge exploit in June that resulted in $89 million in losses. Coldcard's parent company Coinkite released a firmware patch within 72 hours of public disclosure and advised customers to upgrade their devices. TRM Labs noted that devices already compromised could have had keys extracted before the patch was available.
The $1.2 billion figure does not include losses from private key compromise or wallet draining that went unreported. TRM Labs estimates reported theft typically accounts for 40 to 60 percent of total losses. Neither figure includes losses from market manipulation or failed projects that never involved theft but resulted in total user fund loss.