Coldcard Hack Tax Deduction: The July 2026 BTC Theft Loss

A photo of our CEO, Chris Herbst who has degrees in both accounting and computer science - the very tools needed to handle crypto tax reporting correctly.
By Chris Herbst
Managing Director at global crypto tax reporting firm, CountDeFi & CH Consulting
GTP, CIBA
Category:
Published:
Updated:
Update Due:
IRS
August 20, 2026
August 20, 2026
June 16, 2027
If you held the drained bitcoin as an investment, the Coldcard hack tax deduction is an IRC 165 theft loss on Form 4684 Section B, capped at your cost basis, not the July 2026 market value. The hard parts are proving investment intent, picking the right tax year while the Coinkite litigation is live, and rebuilding basis for coins cold-stored since 2021.

On 30 July 2026 an attacker began sweeping bitcoin out of wallets whose seeds had been generated on Coldcard hardware devices, and within 25 minutes roughly 594 BTC, close to USD 38 million at the time, had left approximately 500 wallets for a single consolidation address, according to TRM Labs. TRM puts the four waves at roughly 1,816 BTC, about $116 million, drained from over 5,200 addresses, and the holders of those addresses now need an answer on the Coldcard hack tax deduction before Q4 2026 estimated payments, not in April 2027.

I'm Chris Herbst, Managing Director at CountDeFi, a global crypto tax reporting firm specializing in complex cryptocurrency and DeFi reconciliations. I hold the GTP (Global Tax Practitioner) designation and am a member of CIBA (Chartered Institute for Business Accountants). Since 2017 our team has rebuilt cost basis for self-custody wallets with no exchange records behind them, and we have prepared theft and worthlessness positions for clients who lost coins to exchange collapses, protocol exploits and wallet compromises.

This guide is for US individuals who held bitcoin on an affected Coldcard and were drained in the July and August 2026 waves, with a section at the end for victims filing in the UK, Canada, Australia and Germany.

Can you claim a Coldcard hack tax deduction for bitcoin drained from your wallet?

If you held the drained bitcoin as an investment, the deduction available to you is an IRC u0024165 theft loss computed on Form 4684, Casualties and Thefts, Section B, and carried to Schedule A; if the IRS characterizes your holding as general personal property, the deduction is disallowed outright. That single characterization question is worth the entire deduction, and it is the first thing we settle before touching a number.

Why the personal casualty route is dead

IRC u0024165(c) limits an individual's loss deduction to losses incurred in a trade or business, losses incurred in a transaction entered into for profit, and personal casualty and theft losses, as summarised in this practitioner overview of the current guidance. The third category is now closed for events like this. The IRS states that "Section 70109 of the One Big Beautiful Bill Act amended IRC Section 165, so that qualifying deductible individual personal casualty losses shall be allowed only to the extent that they are attributable to either a federally declared disaster or a State declared disaster" (IRS). A firmware bug is not a declared disaster. Form 4684 Section A is therefore not your form.

What IRC 165(c)(2) requires you to show

The live route is u0024165(c)(2), a loss incurred in a transaction entered into for profit. Rev. Rul. 2009-9 holds that a theft loss in a for-profit transaction is a theft loss rather than a capital loss, that it is an itemized deduction outside the u0024165(h) personal loss limits, and that it is deductible in the year of discovery where the loss is not covered by a claim for reimbursement. Investment theft losses are not reduced by the 10% of AGI floor and are reported in Section B of Form 4684.

Is passively held cold-stored bitcoin really investment property?

This is unsettled and there is no case law on self-custodied bitcoin. The favourable reading comes from the IRS's own framework in CCA 202511015, which says that where the taxpayer did not authorise the transfer, "we look to the stolen property... and determine whether they were connected to the taxpayer's trade or business, were invested in for profit, or held as general personal property," and that "the theft of property while invested establishes that Taxpayer 3's loss was incurred in a transaction entered into for profit." The contrary argument is that bitcoin held for spending, for savings, or for sovereignty reasons is general personal property, which pushes the loss into u0024165(c)(3) where u0024165(h)(5) eliminates it. In practice this turns on contemporaneous evidence: prior reported bitcoin gains, rebalancing activity, and how you described the holding at the time.

What happened in the Coldcard exploit, and does the firmware version change your claim?

The exploit was a seed-entropy failure at wallet creation, not a break in bitcoin's cryptography, and the specific firmware version your seed was created on determines whether you were exposed at all. A build configuration error in firmware version 4.0.1, shipped in March 2021, set the macro MICROPY_HW_ENABLE_RNG to zero, which routed seed generation to a deterministic software fallback and cut effective entropy from 128 bits to approximately 40 bits on Mk3 devices and 72 bits on Mk4, Mk5 and Q models (crypto.news).

Which Coldcard firmware versions are in scope

Coinkite's own advisory states the issue is present on Mk2 and Mk3 firmware versions 4.0.1 through 4.1.9 inclusive, on Mk4 and Mk5 seeds generated before standard version 5.6.0 or Edge version 6.6.0X, and on Q before standard version 1.5.0Q or Edge version 6.6.0QX (Coinkite). The advisory was updated on 31 July 2026 at 9:33 a.m. EDT with fixed firmware, directing Mk4 and Mk5 users to 5.6.0 or later, Q users to 1.5.0Q or later and Mk3 users to 4.2.0 or later (Bitcoin Magazine). Coinkite has stated that installing corrected firmware does not repair a seed generated under the earlier version (Epoch Times). Record the model, the serial number and the firmware version string in your file; it is the causation link between the published defect and your drained address.

Dice rolls, passphrases, and who does not have a loss

Coinkite says that on affected firmware the device hashed the seed together with every dice roll entered, so 50 to 98 independent, private rolls contributed at least 128 bits of entropy on their own, and that a strong, unique BIP-39 passphrase adds an independent barrier that reduced seed entropy alone cannot defeat. If you used dice or a passphrase and were still drained, your causation story is harder, because the theft may have another cause, and that affects both the tax position and any claim against Coinkite. If you moved funds after the advisory and were never drained, you have no u0024165 loss at all, only network fees, and possibly a taxable disposal if you swapped assets during the migration. Whether migration costs incurred to escape a defective product are deductible is unaddressed in guidance; treat it as unverified.

Which tax year does the Coldcard theft loss belong in, 2026 or 2027?

All four waves fell between 30 July and early August 2026, so for a calendar-year US individual the event sits in the 2026 tax year, but the deduction year is keyed to discovery and to whether a claim for reimbursement with a reasonable prospect of recovery existed at year end. Two victims with identical drain transaction hashes can legitimately land in different years.

The discovery year rule

Rev. Rul. 2009-9 holds that the loss is deductible in the year the loss is discovered, provided the loss is not covered by a claim for reimbursement or recovery. A cold-storage holder who checks balances once a quarter may genuinely have discovered the drain in 2027. Document the date and the method of discovery, because there is no third party to corroborate it.

Reasonable prospect of recovery is the real fight

"Reasonable prospect of recovery" is a much lower bar than "recovery is likely," and the facts here cut against victims in an unusual way. TRM reports that stolen funds are pooling at a few attacker addresses with minimal laundering so far, with no layering or mixing, and roughly 90% of the stolen bitcoin remains unmoved. Galaxy Research reported around 600 suspected attacker-controlled addresses to federal investigators and compliance firms, while cautioning that it has not computationally confirmed that every identified address was generated with weak Coldcard entropy. Traceable, unmoved coins are a serviceable IRS argument that a prospect of recovery existed on 31 December 2026. Three positions are defensible: deduct in full for 2026 and treat any later recovery as income under the tax benefit rule; deduct only the portion not covered by a claim; or defer entirely. Option one maximises the 2026 deduction and carries the most audit exposure, and option three risks the statute closing on the correct year. Rev. Rul. 2009-9 is explicit that a later recovery beyond the amount initially covered by a claim "is includible in A's gross income in the later year under the tax benefit rule."

Does the Coinkite class action defeat a 2026 deduction?

Victims are planning class-action lawsuits against Coinkite, and legal commentators are sharply divided on Coinkite's liability. There is no ruling on whether an unfiled but threatened product-liability class action is a claim for reimbursement for these purposes, and practitioners split on whether being a putative class member is different from being a named plaintiff. Treat this as unverified and document your own position as at year end. What would move the answer toward a clean 2026 deduction: a Coinkite bankruptcy, a formal denial of any reimbursement programme, a dismissal, or the attacker moving coins into a mixer. Whether Coinkite has established any compensation programme is unverified; we have found no source either way.

Theft loss or capital loss: which route gives the better Coldcard hack tax deduction?

A u0024165(c)(2) theft loss on Form 4684 Section B produces an ordinary itemized deduction with no $3,000 cap, while reporting the drain on Form 8949 at zero proceeds produces a capital loss usable against gains and then $3,000 of ordinary income. We prefer the theft loss where the taxpayer itemizes and the investment-intent record is strong, because Rev. Rul. 2009-9 is explicit that this is a theft loss and not a capital loss.

Reporting routeHow it offsets incomeStatus for Coldcard victims
Form 4684 Section B theft lossOrdinary, no dollar capProfit motive contested
Form 8949 at zero proceedsCapital, $3,000 ordinary capConflicts with Rev. Rul. 2009-9
Form 4684 Section A casualtyDeclared disasters onlyDisallowed
Rev. Proc. 2009-20 safe harbor95% or 75% of investmentNot available

The case for Form 8949 anyway

The theft loss is an itemized deduction. A taxpayer whose loss plus other itemized deductions falls below the standard deduction gets nothing from it, while a capital loss offsets gains and then $3,000 of ordinary income regardless of itemizing, and carries forward. That is a genuine planning fork, not a hedge, and it is worth modelling both before filing. The counterargument is technical: CCA 202302011 insists that u0024165 requires losses "evidenced by closed and completed transactions, fixed by identifiable events, and actually sustained during the taxable year," and a drained UTXO is not a sale you elected to make. If you go the Form 8949 route, our Form 8949 and Schedule D guide sets out the mechanics.

Never file both

Claiming the same coins as an ordinary theft loss and as a capital loss is the fastest route to an examination. Pick a route, document the reasoning contemporaneously, and keep the analysis in the file. Our broader crypto scam and theft loss guide walks the same fork for non-Coldcard events.

How much of the Coldcard hack tax deduction do you actually get?

Your deductible loss is limited to your basis in the stolen bitcoin under IRC u0024165(b) and u00241011, not the market value on 30 July 2026, so a 2021 buyer loses the appreciation with no deduction for it. Form 4684 Section B still asks for fair market value before and after the theft, so you must pin and document a price source and timestamp inside the relevant drain window even though the deduction is capped away by basis.

Net operating losses and the 80% limit

A u0024165(c)(2) theft loss can create or increase an NOL, because IRC u0024172(d)(4)(C) treats casualty and theft losses allowable under u0024165(c)(2) or (3) as attributable to a trade or business, taking them outside the nonbusiness deduction limitation. The NOL deduction attributable to post-2017 losses is limited to 80 percent of taxable income for taxable years beginning after 31 December 2020 under u0024172(a)(2)(B)(ii). For a retail holder with a modest basis this rarely matters; for a large 2021 accumulation it changes the multi-year picture.

The 2026 itemized deduction haircut nobody has addressed

Investment theft losses historically sat outside the u002468 phaseout. For tax years beginning after 31 December 2025, itemized deductions are reduced by 2/37 of the lesser of total itemized deductions or the amount by which income exceeds the 37% bracket threshold under the new u002468 formula, with 2026 thresholds reported at $640,600 for single filers and $768,700 for married filing jointly (summary). Whether the new u002468 reaches a u0024165(c)(2) theft loss the way the old u002468 did not is not addressed in any guidance we have found. It is unverified, and a high earner claiming a large 2026 Coldcard loss should expect to take a position on it.

Does the Ponzi safe harbor apply to the Coldcard hack tax deduction?

No. Rev. Proc. 2009-20 requires a qualified loss from a specified fraudulent arrangement for which authorities have charged the lead figure by indictment, information or criminal complaint, as restated in Rev. Proc. 2011-58, and the Coldcard event fails on both limbs: it is not a fraudulent investment arrangement, and nobody has named the attacker.

The IRS has already run this argument

In CCA 202511015 the IRS applied exactly this reasoning against a pig-butchering victim, concluding that the loss did not meet the qualified loss criteria because no indictment or criminal charge was filed against the scammer, per this breakdown of the memorandum. The safe harbor election must also be made in the discovery year, defined as the year the lead figure was charged.

The software trap

Tax software that auto-classifies any Form 4684 Section B entry as a Ponzi loss will produce a wrong return. The Form 4684 instructions for Rev. Proc. 2009-20 claimants direct the deductible theft loss to line 28 of Section B Part I and skip lines 19 through 27, with a signed statement attached; line numbering should be re-checked against the 2026 form. Filing that statement when you do not qualify is an unforced error, and it is the sort of thing our crypto tax software review flags routinely.

How do you evidence the Coldcard theft to the IRS?

Because Coldcard is an air-gapped signing device rather than a custodian, there is no operator to issue a statement, so the entire evidence file is self-constructed from chain data, the vendor advisory and third-party attribution work. IRS Publication 547 states that "a theft is the taking and removing of money or property with the intent to deprive the owner of it," that the taking must be illegal under the law of the state where it occurred and done with criminal intent, and that "you don't need to show a conviction for theft."

The chain and device file

Build it address-specific and hash-specific: your drained addresses, the source UTXOs, the drain transaction hashes and timestamps, the attacker consolidation addresses, the Coldcard model and serial, the firmware version string, and the Coinkite advisory URL. You still physically hold the device, which is unusually strong ownership evidence. The tracker at coldcardentropy.org publishes a confirmed-core dataset for the 30 July coordinated sweep covering 500 transactions, 1,324 source UTXOs, 500 unique source addresses and 594.51379184 BTC in source input, and it labels the larger address sets circulating in press coverage as attributed or provisional. Cite the dataset for context, not as proof that your address was affected.

Attribution reports and law enforcement

A TRM Labs or Chainalysis style attribution report tying your address to the exploit cluster, plus a police or IC3 report number, plus a written determination as at 31 December 2026 about the Coinkite litigation, is the file we want to see. Note that if the property is covered by insurance, a timely claim must be filed or the loss cannot be deducted as a casualty or theft loss, per this summary of the rules, which also confirms that theft losses of income-producing property are figured in Section B of Form 4684 and carry to Schedule A, line 16. Keeping this material organised now is the same discipline described in our IRS crypto record keeping guide, and it is what stands between you and an examination you cannot answer.

Where did the theft legally occur?

Publication 547 requires the taking to be illegal under the law of the state where it occurred, and nobody has published a situs analysis for a purely computational key-recovery theft. The device sat in one state, the key was derived on unknown hardware in an unknown jurisdiction, and the UTXO moved on a global ledger. Practitioners disagree on whether the victim's state of residence supplies the governing law. This is unverified; the comfort factor is that no conviction is required.

How do you reconstruct basis for bitcoin cold-stored since 2021?

You reconstruct it from acquisition-side records and chain history, because there is no broker statement anywhere in the chain for coins bought in 2021 and swept into self-custody. Brokers must report gross proceeds for transactions effected on or after 1 January 2025 and basis on certain transactions effected on or after 1 January 2026 on Form 1099-DA, and none of that reaches a self-custody wallet. You will receive no 1099-DA and no 1099-B for the drained coins.

If you did the Rev. Proc. 2024-28 allocation, you are in good shape

The Rev. Proc. 2024-28 safe harbor allowed taxpayers to allocate unused basis of digital assets to other digital assets held within each wallet or account as of 1 January 2025, and it was available only to holders who acquired the units before that date and held them in the wallet as of that date, per this firm alert. If you did the allocation, you have a documented basis figure attached to the exact Coldcard wallet that was drained, which is the single best piece of evidence available. Our explainer on Rev. Proc. 2024-28 and on universal versus wallet-based tracking covers what that allocation looks like in practice.

If you did not, FIFO is the default

Under the final regulations, absent specific identification prior to or at the time of sale, FIFO applies, though taxpayers who self-custody can adopt a standing rule in their books and records identifying units selected for disposal (RSM). Applying a standing rule retroactively to a wallet that is now empty invites a challenge. If the exchange you bought from in 2021 has since closed, our guide on getting records from a dead exchange lists the reconstruction sources we use, and our note on missing transaction data covers documenting the method itself.

A UTXO is not a tax lot

The drain transactions are precise to the satoshi, but change outputs, consolidations and multi-input spends over five years mean the coin that left address X on 30 July 2026 can be an amalgam of six acquisitions at six different prices. Sats-level precision on chain does not produce lot-level precision on Form 4684.

Partial drains and mixed wallets

A device that held the affected seed plus a passphrase-protected sub-wallet may be only partly drained, and there is no prescribed method for allocating basis between the drained and surviving portions. Doing it after the fact invites a specific-identification challenge, so document the allocation logic and apply it consistently.

Where does Coldcard theft loss reporting actually break down?

The reporting breaks down at the point where every figure on the return has to be self-constructed with no counterparty, no export and no consensus victim list. These are the failure points we see most often on this event:

  • No tax export exists. Coldcard is not a broker under the u00246045 regulations and issues no statements of any kind.
  • Competing loss totals. TRM reports roughly 1,816 BTC from over 5,200 addresses across four waves; Galaxy Research verified 1,596 BTC from approximately 7,300 addresses across three waves with a suspected fourth bringing the total to roughly 2,055 BTC, around $130 million (Crystal Intelligence). You cannot cite "the" loss figure; your evidence must be your own addresses.
  • Wave-specific pricing. Different waves happened on different days at different prices. As of 1 August 2026 three waves had swept 1,367 BTC, nearly $89 million, from 4,585 addresses (CoinDesk), and a third wave alone added 208 BTC drawn from 1,912 addresses.
  • Non-itemizers get nothing. A Section B loss carries to Schedule A, line 16, so a holder with a $20,000 basis and no other large deductions receives no federal benefit from the theft route.
  • State conformity is unresolved. Whether a state that decoupled from TCJA still allows the loss, and whether it follows the u0024165(c)(2) and u0024165(c)(3) split the same way, varies. We found no state-specific source; treat it as unverified and check your state individually.

How is the Coldcard theft treated outside the US?

The four major non-US regimes split sharply, with Australia the most accommodating, the UK and Germany structurally hostile, and Canada silent despite Coinkite being a Canadian company.

United Kingdom

HMRC's manual is blunt: "HMRC does not consider theft to be a disposal, as the person still owns the stolen asset and has a right to recover it. This means victims of theft cannot claim a loss for Capital Gains Tax or Corporation Tax" (CRYPTO41550). The workaround practitioners point to is a negligible value claim under s.24 TCGA 1992, described at CRYPTO22500, which treats tokens as disposed of and immediately reacquired at a stated amount. Because tokens are pooled, the claim must be made for the whole section 104 pool, which is a structural problem for a victim who also holds unaffected BTC in the same pool. Whether HMRC would accept a negligible value claim for coins a third party demonstrably controls is unverified. UK victims fall in tax year 2026/27, and if you have older unreported disposals sitting behind this, see our guide to a voluntary disclosure to HMRC.

Canada

There is no CRA pronouncement on stolen crypto specifically. CRA has said that where a virtual currency such as Bitcoin is lost or stolen, IT-185R may be of assistance, and IT-185R was cancelled in December 2014 and replaced by Income Tax Folio S3-F9-C1, whose operative rule at 1.33 is a business rule about trading assets lost through theft or embezzlement. That does little for a passive investor holding capital property. Canadian commentary also flags a possible postponement under subsection 44(1) where property is stolen; its relevance to an ordinary victim is unverified. If you are Canadian and expect scrutiny, our note on CRA crypto audits covers what the letters look like.

Australia

The ATO is the most taxpayer-friendly of the four and has guidance directly on point: "If your crypto asset is lost or stolen, you can claim a capital loss if you can provide evidence of ownership," and "if you receive a compensation or insurance payment because your crypto asset is lost or stolen, you must reduce your capital loss" (ATO). The evidence bar is specific: acquisition date of the crypto or private key, the date access was lost, the wallet address, acquisition cost, and value when access was lost, plus evidence you controlled the wallet and possess the hardware. A Coldcard owner still holding the device satisfies that last limb unusually well. Australian victims fall in the 2026-27 income year; see our Australian crypto tax guide.

Germany

Crypto is treated as an "anderes Wirtschaftsgut" under u002423(1) sentence 1 no. 2 EStG per the BMF letter of 6 March 2025, Rz. 53, confirmed by the Bundesfinanzhof judgment of 14 February 2023, IX R 3/22. Because u002423 taxes private disposal transactions, theft, private key loss and hacks are not a Veraeusserungsvorgang and produce no deductible loss (Blockpit). Coins cold-stored since 2021 would have been outside the one-year speculation period anyway, so German holders lose both the exemption and any relief. Where a loss is recognisable it goes in Anlage SO, which now carries a dedicated Kryptowerte section, and the former 20,000 euro loss-offset restriction in u002420(6) sentence 5 EStG was repealed by the Jahressteuergesetz 2024 with effect from assessment period 2025.

What are the most common mistakes with the Coldcard hack tax deduction?

The mistakes we see cluster around characterization, timing and basis, and each one is fixable before filing rather than after an examination.

Deducting the market value instead of basis

The deductible loss is limited to basis under u0024165(b) and u00241011. A holder who bought at 2021 prices and lost coins worth several times that in July 2026 cannot deduct the appreciation, and claiming it is the single fastest way to draw scrutiny.

Filing Section A of Form 4684

Section A is for personal-use property and, for tax years beginning after 2017, allows a loss only where it is attributable to a federally declared disaster. Using it here produces a disallowed deduction and a wrong return.

Asserting no prospect of recovery instead of documenting it

With roughly 90% of the stolen bitcoin unmoved and litigation threatened, "no reasonable prospect of recovery" is a conclusion you have to build a file for, not a sentence you write on a worksheet.

Letting software model the drain as a sale

Most crypto tax tools will treat an outgoing transaction with no matching receipt as a disposal at zero proceeds. That may be the route you choose deliberately, but it should be a decision, not a default, and it should never be paired with a Form 4684 claim on the same coins. If you also harvested losses this year, coordinate the two; our tax loss harvesting guide covers year-end sequencing, and remember the wash sale rule position for crypto is its own question.

Do You Need Help With Your Coldcard Theft Loss?

If your addresses appear in the Coldcard drain waves, the work ahead is a basis reconstruction across five years of self-custody, a characterization decision on u0024165(c)(2) versus a capital loss, and an evidence file that holds up if the IRS asks why you took the deduction in 2026 rather than 2027. None of that is a software output.

CountDeFi Is Your Coldcard Hack Tax Deduction Solution

We are not just accountants at CountDeFi, we are data scientists who work exclusively on crypto, which is why we start with your UTXO history rather than a spreadsheet of guesses. Headquartered in Oregon, we have worked with more than 1,000 clients globally since 2017, rebuilding cost basis for wallets with no exchange records and preparing theft loss positions with the documentation to support them. If you were drained on 30 July 2026 or in the waves that followed, book a free call with one of CountDeFi's crypto tax specialists and we will tell you honestly whether you have a deduction worth claiming. If you want to understand pricing first, see our guide to what a US crypto CPA costs.

Frequently Asked Questions

Can I deduct my bitcoin stolen in the Coldcard hack?

If you held the bitcoin as an investment, you can claim an IRC 165 theft loss on Form 4684 Section B, limited to your cost basis. If the IRS treats the holding as personal property, section 165(h)(5) disallows it.

Do I pay tax on bitcoin that was stolen from my Coldcard?

No. A theft is not a disposal that produces a capital gain, so you do not owe capital gains tax on appreciation you never realised.

Does getting hacked count as a sale for tax purposes?

Not under Rev. Rul. 2009-9, which treats a theft in a for-profit transaction as a theft loss rather than a capital loss. Some preparers still report it on Form 8949 at zero proceeds, which is a different route with different consequences.

Can I deduct the full July 2026 value of my bitcoin or only what I paid for it?

Only what you paid. The deduction is limited to your basis under IRC 165(b) and 1011, so the appreciation from 2021 to July 2026 is lost with no deduction attached to it.

Do I need a police report to claim the Coldcard theft loss?

Publication 547 does not require a conviction, but a police or IC3 report number is standard evidence and we would not file without one.

What firmware version was affected by the Coldcard entropy bug?

Coinkite's advisory identifies Mk2 and Mk3 firmware 4.0.1 through 4.1.9 inclusive, Mk4 and Mk5 seeds generated before 5.6.0 standard or 6.6.0X Edge, and Q seeds generated before 1.5.0Q standard or 6.6.0QX Edge.

Was my Coldcard Mk3 running 4.0.1 affected?

Firmware 4.0.1 is the version in which the build configuration error was introduced in March 2021, and on Mk3 devices effective entropy fell to approximately 40 bits. Coinkite says installing corrected firmware does not repair a seed generated under the defective version.

Does a BIP-39 passphrase mean I cannot claim a theft loss?

If you were not drained, you have no loss to claim. Coinkite states that a strong, unique passphrase adds an independent barrier that reduced seed entropy alone cannot defeat, so a drained passphrase wallet has a different causation story to document.

I used dice rolls on my Coldcard, do I still have a loss?

Only if funds actually left your addresses. Coinkite says 50 to 98 independent, private dice rolls contributed at least 128 bits of entropy on their own, so a drain despite dice suggests another cause you will need to evidence.

Which Coldcard hack wave was my wallet in, and does it change my tax year?

All four waves ran from 30 July 2026 into early August 2026, so the event year is 2026 for calendar-year filers. The wave affects the price you use for fair market value, not the year.

How do I find the drain transaction hash for my Coldcard address?

Look up your receiving addresses on any block explorer and identify the spend you did not authorise, then record the transaction hash, timestamp, source UTXOs and destination address.

Do I need a TRM Labs or Chainalysis report to prove the Coldcard theft to the IRS?

It is not legally required, but an attribution report linking your address to the exploit cluster is the strongest third-party evidence available for a self-custody theft with no counterparty.

Is coldcardentropy.org enough evidence for the IRS?

On its own, no. The tracker labels the larger address sets circulating in press coverage as attributed or provisional rather than definitive victim counts, so your evidence must be specific to your own addresses and hashes.

My Coldcard was drained but I still have the device, does that help?

Yes. Possession of the device, its serial number and its firmware version links the published defect to your wallet, and for Australian filers the ATO specifically asks for evidence you possess the hardware.

What form do I use to claim the Coldcard theft loss?

Form 4684, Casualties and Thefts, Section B, for business and income-producing property, with the result carried to Schedule A.

Form 4684 Section A or Section B for stolen crypto?

Section B. Section A covers personal-use property, which since 2018 is deductible only for losses attributable to a federally declared disaster, and from 2026 state declared disasters.

Does the Coldcard theft loss go on Schedule A line 16?

Yes. Theft losses of income-producing property are figured in Section B of Form 4684 and carry to Schedule A, line 16, in the year the loss is discovered.

Can I claim the Coldcard loss if I take the standard deduction?

No. The theft loss is an itemized deduction, so a holder whose itemized deductions do not exceed the standard deduction receives no federal benefit from it.

Can a crypto theft loss create a net operating loss?

Yes. IRC 172(d)(4)(C) treats theft losses allowable under section 165(c)(2) as attributable to a trade or business, so they can generate an NOL, subject to the 80 percent of taxable income limit for post-2017 losses.

Should I report the Coldcard hack on Form 8949 instead of Form 4684?

It is a genuine planning fork. Form 8949 at zero proceeds produces a capital loss capped at $3,000 against ordinary income but usable without itemizing, while Form 4684 produces an uncapped ordinary itemized deduction that conflicts with nothing in Rev. Rul. 2009-9.

Does the Rev. Proc. 2009-20 Ponzi safe harbor apply to the Coldcard hack?

No. The safe harbor requires a specified fraudulent arrangement with a lead figure charged by indictment, information or criminal complaint, and no one has named the Coldcard attacker.

What tax year do I claim the Coldcard theft loss, 2026 or 2027?

The loss is deductible in the year of discovery, provided it is not covered by a claim for reimbursement with a reasonable prospect of recovery. Most victims discovered the drain in 2026, but the recovery question is what actually decides the year.

Can I claim the Coldcard loss in 2026 if the class action against Coinkite is still going?

That is unsettled. There is no ruling on whether an unfiled but threatened product-liability class action creates a claim for reimbursement, and practitioners split on whether a putative class member is in the same position as a named plaintiff.

What does reasonable prospect of recovery mean for the Coldcard hack?

It is a lower bar than recovery being likely. With roughly 90% of the stolen bitcoin unmoved and around 600 suspected attacker addresses reported to federal investigators, the IRS has a serviceable argument that a prospect existed at 31 December 2026.

If Coinkite pays me later, do I have to pay tax on the settlement?

Rev. Rul. 2009-9 says a recovery beyond the amount covered by a claim is includible in gross income in the later year under the tax benefit rule. The character of a fiat product-liability settlement paid for stolen BTC is unaddressed in guidance and remains unverified.

What if I discovered my Coldcard was drained in 2027 instead of 2026?

Then your discovery year is 2027 and the deduction belongs there, provided you can document when and how you discovered the loss.

How do I calculate cost basis for bitcoin I cold-stored in 2021 with no exchange records?

You rebuild it from bank statements, email confirmations, chain history, peer-to-peer records or mining logs, and you document the method itself. Without specific identification, the final regulations default you to FIFO.

The exchange I bought my bitcoin from in 2021 no longer exists, how do I prove basis?

Reconstruct from the funding side: bank or card records of the fiat payment, the on-chain withdrawal to your wallet, and contemporaneous price data at the timestamp. It is defensible when it is consistent and documented.

Do I get a 1099-DA for bitcoin stolen from a self-custody wallet?

No. Broker reporting of gross proceeds began for transactions effected on or after 1 January 2025 and basis on certain transactions from 1 January 2026, and none of it reaches a self-custody Coldcard.

Does the Rev. Proc. 2024-28 allocation matter if my wallet is now empty?

Very much. If you made the allocation you have a documented basis figure attached to the exact wallet that was drained, which is the strongest basis evidence available for this event.

How do I split cost basis when only part of my Coldcard wallet was drained?

There is no prescribed method. Choose a consistent allocation, document the logic contemporaneously, and expect a specific-identification challenge if you construct it after the fact.

Can I claim a capital loss for the Coldcard hack in the UK?

Not for the theft itself. HMRC's CRYPTO41550 states that theft is not a disposal and that victims cannot claim a loss for Capital Gains Tax or Corporation Tax.

Can I make a negligible value claim for stolen bitcoin in the UK?

CRYPTO22500 allows a negligible value claim where tokens become of negligible value while owned, and it must be made for the whole section 104 pool. Whether HMRC accepts one for coins a third party controls is unverified.

How does the CRA treat crypto stolen from a hardware wallet?

There is no CRA pronouncement on point. CRA has pointed to IT-185R, which was cancelled in December 2014 and replaced by Folio S3-F9-C1, whose deductibility rule is written for business trading assets rather than capital property.

Can I claim the Coldcard loss on my Australian tax return?

The ATO permits a capital loss for lost or stolen crypto where you can provide evidence of ownership, and requires you to reduce that loss by any compensation or insurance payment received. Australian victims fall in the 2026-27 income year.

Are hacked crypto losses deductible in Germany under section 23 EStG?

No. Theft, private key loss and hacks are not a disposal for section 23 EStG purposes, and without a disposal there is no deductible loss.

Chris Herbst is the founder of CountDeFi, a crypto tax specialist with degrees in both accounting and computer science, and a registered Tax Professional (GTP, CIBA). This article is for educational purposes only and does not constitute tax, legal, or investment advice. Consult a qualified tax professional for guidance specific to your situation.

Let's get your crypto taxes done.

Book a free, no-obligation exploratory call with us.