Coldcard Hack Losses Hit $130M as 15 Attackers Join In
- Galaxy Research says the Coldcard exploit is now being used by at least 15 different attackers.
- We’re looking at estimated losses of about 2,055 BTC, worth roughly $130 million.
- Verified thefts already top $100 million and involve more than 7,300 affected addresses.
The Coldcard hardware wallet exploit has widened from a handful of coordinated attackers into what Galaxy Research now describes as an open free-for-all. At least 15 separate actors are racing to drain vulnerable wallets before the rest get moved to safety.
Confirmed losses stand at 1,596 BTC, worth just over $100 million and these were taken from roughly 7,300 addresses across three verified attack waves plus 14 smaller incidents. Add a suspected fourth wave that Galaxy hasn’t fully confirmed, and the total climbs closer to 2,055 BTC, near $130 million.
Coldcard Exploit Expands From One Attack Chain to Multiple Actors
Most hardware wallet breaches trace back to a single group working one exploit chain. This one didn’t stay that way. Galaxy’s Head of Research, Alex Thorn, said the firmware flaw is now being worked by numerous independent actors rather than one coordinated operation. Once the technical details of an exploit like this circulate publicly, anyone with the skill to reproduce it can join in, and that’s exactly what’s happened here.
The bug itself lives in a seed-generation flaw in certain Coldcard firmware versions. Attackers can guess private keys without ever touching the physical device. That undermines the core promise of offline storage in the first place. Coinkite, the manufacturer, has pushed emergency firmware for every affected model and destroyed remaining vulnerable inventory.
None of that protects funds already generated on a compromised seed, though. Users still need to generate a brand-new recovery phrase on corrected firmware and move their Bitcoin. Galaxy says a meaningful share of affected owners still hadn’t done that more than a week after the flaw went public.
Why the Coldcard Threat May Continue to Grow
Roughly 90% of the stolen Bitcoin has not moved on-chain, which Galaxy has flagged as both a warning sign and an opportunity. Static coins remain traceable, and the firm continues sharing attacker and victim addresses with law enforcement and exchanges in hopes of intercepting funds before they’re laundered.
Competing wallet makers Ledger, Trezor, and Bitkey have each confirmed their devices don’t share the flaw. For Coldcard users, the operative question isn’t whether the exploit is over. Galaxy has been explicit that it isn’t, and that new opportunistic attackers keep appearing as the vulnerability details continue to circulate across security forums and social media.
Sources: