Skip to content
Crypto News Today

Coldcard Hack Losses Hit $130M as 15 Attackers Join In

Illustration of a cassette tape labeled “Galaxy Research with Alex Thorn” featuring bitcoin symbols, set against an orange textured background with the headline “Coldcard Wallet Hack Expands as 15 Attackers Push Losses Toward $130M,” representing Galaxy Research’s investigation into the widening Coldcard wallet exploit.
  • Galaxy Research says the Coldcard exploit is now being used by at least 15 different attackers.
  • We’re looking at estimated losses of about 2,055 BTC, worth roughly $130 million.
  • Verified thefts already top $100 million and involve more than 7,300 affected addresses.

The Coldcard hardware wallet exploit has widened from a handful of coordinated attackers into what Galaxy Research now describes as an open free-for-all. At least 15 separate actors are racing to drain vulnerable wallets before the rest get moved to safety.

Contents

Confirmed losses stand at 1,596 BTC, worth just over $100 million and these were taken from roughly 7,300 addresses across three verified attack waves plus 14 smaller incidents. Add a suspected fourth wave that Galaxy hasn’t fully confirmed, and the total climbs closer to 2,055 BTC, near $130 million.

Coldcard Exploit Expands From One Attack Chain to Multiple Actors 

Most hardware wallet breaches trace back to a single group working one exploit chain. This one didn’t stay that way. Galaxy’s Head of Research, Alex Thorn, said the firmware flaw is now being worked by numerous independent actors rather than one coordinated operation. Once the technical details of an exploit like this circulate publicly, anyone with the skill to reproduce it can join in, and that’s exactly what’s happened here.

https://x.com/intangiblecoins/status/2084584185528746434

The bug itself lives in a seed-generation flaw in certain Coldcard firmware versions. Attackers can guess private keys without ever touching the physical device. That undermines the core promise of offline storage in the first place. Coinkite, the manufacturer, has pushed emergency firmware for every affected model and destroyed remaining vulnerable inventory. 

None of that protects funds already generated on a compromised seed, though. Users still need to generate a brand-new recovery phrase on corrected firmware and move their Bitcoin. Galaxy says a meaningful share of affected owners still hadn’t done that more than a week after the flaw went public.

Why the Coldcard Threat May Continue to Grow 

Roughly 90% of the stolen Bitcoin has not moved on-chain, which Galaxy has flagged as both a warning sign and an opportunity. Static coins remain traceable, and the firm continues sharing attacker and victim addresses with law enforcement and exchanges in hopes of intercepting funds before they’re laundered.

Competing wallet makers Ledger, Trezor, and Bitkey have each confirmed their devices don’t share the flaw. For Coldcard users, the operative question isn’t whether the exploit is over. Galaxy has been explicit that it isn’t, and that new opportunistic attackers keep appearing as the vulnerability details continue to circulate across security forums and social media.

Sources:

Galaxy Research post on X.com

Alex Thorn’s Post on X.com