The Coldcard exploit drained over $70M in Bitcoin from almost 1,200 wallets. If you were one of the victims, I’m sorry. I’ve already seen a handful of posts asking whether the loss is deductible, and I’ve seen some confidently wrong answers, so here’s the actual analysis.

I’m a CPA specializing in crypto tax, mod of r/CryptoTax, and Principal of Product & Tax Strategy at Summ. I wrote a guide last year on whether crypto scams are tax deductible based on CCA 202511015, the IRS Chief Counsel Advice released in March 2025. The Coldcard exploit runs through the same framework, but it’s a different fact pattern than the scams the CCA covers, and in one way it’s actually a cleaner case. In another way it’s messier. Both matter for your return.

Disclaimer: Not tax advice, educational purposes only, US taxpayers only, consult your own tax professional.

Quick summary before you read:

Yes, this should qualify as a deductible theft loss under IRC §165(c)(2) for most victims, but timing is key Your deduction is limited to your COST BASIS, not the fair value of the lost assets. You never paid tax on the unrealized gains, so you don’t get to claim that amount as a taxable loss. The year you can claim it is the real problem. You may not be able to deduct it in 2026 The Ponzi safe harbor (Rev. Proc. 2009-20) does not apply here Document everything now What actually happened

Quick recap for anyone catching up. A firmware bug in Coinkite’s Coldcard wallets (sitting in the code since March 2021) routed seed generation to a weak software random number generator instead of the hardware chip. The result: seeds that were supposed to be unguessable were reduced to a range a computer can search. The attacker generated candidate seeds offline, derived the addresses, checked them against the blockchain, and swept the funds. Your device was never touched. It could have been powered off in a safe and the outcome would be the same.

This matters for tax purposes because it means you didn’t do anything. Nobody tricked you into sending funds. That distinction drives the whole analysis.

Why this qualifies under §165(c)(2)

IRC §165(c)(2) allows individuals to deduct theft losses incurred in a transaction entered into for profit. Since 2018, this is essentially the only path for individuals, because personal theft losses under §165(c)(3) are disallowed (more on that below).

The IRS laid out the framework in CCA 202511015, which analyzed five scam victims. The key question in every scenario: did the victim have a profit motive? For victims who authorized transfers (pig butchering, fake fraud department calls), the IRS looked at why they transferred the funds. Investment motive = deductible. Romance or fake ransom motive = not deductible.

But the scenario that matters for Coldcard victims is Taxpayer 3, the phishing victim. Taxpayer 3 never authorized anything. A scammer stole their login credentials and drained their accounts directly. The IRS said that when the taking is unauthorized, you don’t analyze any transfer (there wasn’t one). Instead, you look at why the taxpayer held the stolen property in the first place. Taxpayer 3 held investments in those accounts to grow them for retirement, so the loss was incurred in a transaction entered into for profit and was deductible under §165(c)(2).

Footnote 15 of the CCA makes it explicit: for losses from “hacked” accounts where hackers cause an unauthorized distribution, “the analysis and Federal income tax consequences are the same as for victims of phishing scams.”

That’s the Coldcard exploit. An unauthorized taking, no victim action, no deception. If you held that BTC as an investment (and if it was sitting in cold storage for years, you almost certainly did), your loss lands squarely in §165(c)(2). In some ways this is an easier case than the scams in the CCA, because there’s no motive-for-the-transfer analysis for the IRS to pick apart. The theft itself is also not seriously in doubt: sweeping funds with reconstructed private keys is larceny and/or computer fraud in essentially every state, and §165 defines theft broadly (Rev. Rul. 2009-9).

One caveat: if you can’t establish an investment purpose (say you held BTC purely to spend), the loss falls into §165(c)(3) personal casualty territory, and those losses are disallowed unless attributable to a declared disaster. The OBBBA made that disallowance permanent, so it applies in 2026 and beyond. For hardware wallet holders this will be rare, but it’s why documentation of your holding intent matters.

Catch #1: your deduction is your basis, not the value

§165(b) limits the deduction to your adjusted cost basis in the stolen property. Not the fair market value on July 30.

If you bought 10 BTC for $30,000 in 2017 and it was worth $650,000 when it was swept, your theft loss deduction is $30,000. The unrealized gain was never taxed as income, so you can’t deduct it as a loss. I know that stings. It’s the same rule that applied to every victim in the CCA, and there’s no way around it.

Also worth understanding: the theft is not a sale. There’s no capital gain event, no capital loss. The lots just exit your records through the theft loss.

Catch #2: the timing problem (this is the big one)

Under §165(e), a theft loss is deductible in the year you discover it. But there’s a second requirement that I think will trip up a lot of Coldcard victims: no deduction is allowed while you have a reasonable prospect of recovery (Treas. Reg. §1.165-1(d)(3)). If a bona fide claim exists with a substantial possibility of success, the loss isn’t “sustained” yet, and you wait.

In the CCA scenarios this was easy. The scammers were anonymous, the funds went overseas, and law enforcement told every victim there was little to no prospect of recovery. Deduction allowed in the discovery year.

The Coldcard facts look different, at least right now:

The stolen BTC is sitting unmoved in four identifiable addresses that everyone is watching Investigators traced the attacker’s workflow to a paid account at a blockchain data provider and handed the logs to authorities Coinkite’s CEO publicly accepted “full accountability” for the firmware bug, and Coinkite is a solvent company. That’s a potential negligence claim Law firms are already soliciting Coldcard victims for litigation

None of that means you’ll ever see your coins again. But “reasonable prospect of recovery” is a much lower bar than “recovery is likely,” and if you claim the full loss on your 2026 return while a class action against Coinkite is live and the coins are traceable, you’re taking a position the IRS can challenge on timing. The good news is the standard cuts both ways: the courts say you don’t have to be an “incorrigible optimist.” If by December 31 the coins have been laundered through mixers, no suspect has been identified, and you have a documented basis for concluding claims against Coinkite are unlikely to go anywhere (or you’ve opted out of litigation), a 2026 deduction becomes defensible. If recovery prospects resolve later, you deduct in the year they resolve.

Practical translation: don’t assume this goes on your 2026 return. Watch how the investigation and any Coinkite litigation develop, and make the call with your tax professional based on the facts as of year end.

No Ponzi safe harbor

Some people will suggest the Rev. Proc. 2009-20 safe harbor (the “Ponzi loss” election, 75%/95% of the loss with reduced audit friction). It doesn’t apply here. The safe harbor requires a “specified fraudulent arrangement” where a lead figure takes investor money and reports fake income, AND that lead figure must be criminally charged. The Coldcard attacker never purported to invest anything for anyone, never reported fictitious returns, and hasn’t been identified, let alone charged. Same conclusion the CCA reached for its victims. You’re under the general §165 rules, including the timing rules above.

How to report it (when the time comes)

The loss goes on Form 4684, Section B (income-producing property), then flows to Schedule A as an itemized deduction. It is NOT a miscellaneous itemized deduction, so the old 2% floor and the §67(g) suspension don’t touch it. The 10% AGI floor for personal casualty losses doesn’t apply either, because this isn’t a §165(c)(3) loss.

What to do right now If you still have funds on a potentially affected Coldcard, move them. Coinkite has fixed firmware out, and researchers warned more sweeps are likely File a police report and an IC3 complaint. Every CCA victim had a law enforcement report, and it’s your best evidence for both the theft and the recovery analysis Lock down your cost basis records now. Exchange records, wallet histories, the works. Your basis is your deduction, and you’ll need to prove it Document your holding intent (long-term investment) and keep evidence the specific addresses drained were yours Track the recovery situation: the four addresses, the investigation, any Coinkite litigation. Keep a file. Whichever year you claim the loss, you’ll want a record of why that was the right year Conclusion

The loss is real and the deduction should be too, for anyone who held their BTC as an investment. The CCA’s Taxpayer 3 analysis fits this fact pattern almost perfectly. Just don’t let anyone tell you it’s a simple “write it off in 2026” situation. Your deduction is capped at basis, and the traceable coins plus a manufacturer that publicly took responsibility mean the timing question deserves as much attention as the deduction itself.

Happy to answer questions in the comments.

submitted by /u/JustinCPA [link] [comments]r/CryptoCurrencyRead More

You might also be interested in reading Baytex outlines commercialization plan targeting 20,000–25,000 BOE/d by 2029 amid Duvernay efficiency gains.