Confirmed losses resulting from a sophisticated security incident involving Coldcard wallet users have officially exceeded the $100 million threshold, marking one of the most significant individual hardware wallet-related exploits in recent history. According to the latest comprehensive update from Galaxy Research, the research arm of the digital asset financial services firm Galaxy Digital, approximately 1,596 Bitcoin (BTC) has been illicitly drained from roughly 7,300 unique addresses. The investigation has revealed a systematic pattern of exploitation characterized by three distinct major attack waves, supplemented by 14 smaller, targeted incidents that suggest a multi-layered breach of security protocols.
On Monday, Galaxy Research disclosed that its investigators had been in direct contact with 73 victims who provided detailed accounts of their losses. These victim reports were instrumental in confirming the mechanics of the first three major waves of the attack. By cross-referencing these reports with on-chain data, researchers were able to identify "footprints" of the attackers—specific behavioral patterns and transaction structures that point toward a coordinated effort to exploit a specific vulnerability. Galaxy noted that the smaller, auxiliary incidents likely represent opportunistic actors who recognized the vulnerability and moved to capitalize on it alongside the primary attackers.
Expanding Estimates and Suspected Fourth Wave
While the confirmed loss stands at 1,596 BTC, the actual scale of the incident may be significantly higher. Galaxy Research has identified what it describes as a "suspected fourth wave" of attacks. If this wave is officially confirmed, the total volume of stolen assets could climb to 2,055 BTC, which, at current market valuations, represents a staggering $130 million.
Despite the high probability that this fourth wave is linked to the same exploit, Galaxy has maintained a conservative stance in its official reporting. The firm stated that it excluded these figures from the confirmed estimate because it has not yet received direct verification from the specific victims believed to be affected by this latest movement of funds. However, the research group expressed "medium-high" confidence that the activity associated with this wave is representative of attacker behavior rather than legitimate user migration.
This update represents a sharp escalation from Galaxy’s previous report published on Saturday. In that initial assessment, researchers had traced 1,367 BTC stolen across 4,585 addresses. The rapid discovery of nearly 3,000 additional compromised addresses within 48 hours underscores the speed at which the situation is evolving and the depth of the underlying security flaw.
Technical Analysis of the Attack Methodology
The Coldcard wallet, manufactured by Coinkite, has long been regarded by the Bitcoin community as one of the most secure "air-gapped" hardware wallets available. It is favored by high-net-worth individuals and institutional holders for its Bitcoin-only focus and robust physical security features. The revelation that thousands of addresses have been compromised has sent shockwaves through the self-custody sector.
While the specific technical nature of the vulnerability—whether it stems from a firmware flaw, a seed generation issue (entropy), or a supply chain compromise—is still being scrutinized by independent security experts, the "waves" identified by Galaxy suggest a methodical draining process. In such exploits, attackers often wait for a critical mass of vulnerable addresses to be identified before initiating large-scale transfers to minimize the window for a coordinated defense or firmware patch.
The data indicates that 90% of the stolen Bitcoin currently remains stationary in the attackers’ wallets. This includes the vast majority of funds seized during the first three confirmed waves. In the world of blockchain forensics, "stationary" funds are a double-edged sword. While it means the assets have not yet been laundered through mixers or off-ramped into fiat currency, it also suggests that the attackers are being cautious, likely waiting for the initial investigative intensity to subside or searching for high-liquidity avenues to exit their positions without triggering exchange alerts.
Chronology of the Incident and Response
The timeline of the Coldcard incident reveals a rapidly deteriorating situation that caught many in the security community off guard:
- Initial Detection (Late Last Week): On-chain analysts began noticing unusual transaction patterns involving addresses linked to Coldcard-generated seeds. These transactions were characterized by "sweep" movements where the entire balance of an address was transferred in a single block.
- Saturday, Initial Report: Galaxy Research published its first formal assessment, confirming the loss of 1,367 BTC. The report served as the first major public warning to the Coldcard user base.
- Weekend Escalation: As news spread, more users checked their balances, leading to a surge in victim reports. Researchers began to see the "14 smaller incidents," which suggested that the vulnerability was being discussed or shared in niche cybercrime circles.
- Monday, Major Update: Galaxy confirmed that the number of affected addresses had jumped to 7,300 and the confirmed loss had surpassed the $100 million mark. The identification of the "suspected fourth wave" suggested that the exploit was either ongoing or that the attackers were still processing a backlog of compromised keys.
- Current Status: Galaxy Research, in coordination with other cyber-investigation firms, has shared the identified attacker and victim addresses with United States federal law enforcement agencies and major cryptocurrency exchanges globally.
Official Responses and Industry Impact
The response from the broader crypto-investigative community has been swift. By flagging the attacker addresses, investigators hope to "blacklist" the stolen funds. Most major centralized exchanges (CEXs) utilize automated tools like Chainalysis or Elliptic to monitor incoming deposits. If the attackers attempt to move the 1,596 BTC to an exchange to trade for other assets or fiat, the funds are likely to be frozen immediately.
However, the decentralized nature of Bitcoin means that law enforcement cannot "reverse" these transactions. The recovery of the $100 million depends entirely on either the apprehension of the individuals behind the attack or the accidental exposure of their identities through poor operational security (OpSec).
While Coinkite, the manufacturer of Coldcard, has been a staple in the industry for over a decade, this incident poses a significant reputational challenge. Hardware wallets are marketed as the ultimate defense against remote hacking. When a "cold" wallet is compromised, it calls into question the fundamental "Don’t Trust, Verify" ethos of the Bitcoin ecosystem. If the vulnerability is found to be in the device’s random number generator (RNG) or its implementation of the BIP-39 standard, it could necessitate a massive recall or a fundamental shift in how users generate their private keys.
Broader Implications for Self-Custody and Security
The Coldcard incident serves as a stark reminder that no security solution is infallible. The transition of funds from "hot" (internet-connected) wallets to "cold" (offline) wallets is a standard recommendation for any significant crypto holding, but this event highlights that even cold storage has a "supply chain" of trust involving the hardware manufacturer and the software used to interact with the device.
Industry experts are now emphasizing several key takeaways from this breach:
- Diversification of Custody: High-net-worth holders are increasingly being advised not to rely on a single hardware manufacturer or a single seed phrase. Multi-signature (multisig) setups, which require approvals from multiple different hardware devices (e.g., a combination of Coldcard, Ledger, and Trezor), are being touted as the only way to mitigate the risk of a single-vendor vulnerability.
- The Importance of On-Chain Transparency: The fact that Galaxy Research could identify these waves and track the 90% of unmoved funds is a testament to the transparency of the Bitcoin ledger. This transparency is the primary tool law enforcement has in eventually recovering stolen assets.
- The Threat of AI and Advanced Exploits: As mentioned in related industry reports, the rise of AI-driven tools is making it easier for attackers to scan the blockchain for vulnerabilities and automate the draining of addresses. While this specific Coldcard incident may not be solely AI-driven, the speed and scale of the "waves" suggest a high degree of automation.
Urgent Recommendations for Users
Galaxy Research has issued an urgent warning to all Coldcard users who may be uncertain about the status of their funds. The firm urges users to migrate their Bitcoin to a new, known-safe address immediately. A "known-safe" address would typically involve a seed phrase generated on a different device or through a completely different method (such as dice rolls for entropy) that has not been associated with the suspected vulnerability.
As the investigation continues, the focus remains on the "suspected fourth wave" and the movement of the stationary 90% of funds. If the attackers begin to move these assets through "peel chains" or privacy-enhancing protocols like CoinJoin, the chances of recovery will diminish significantly. For now, the crypto industry remains on high alert, watching the 1,596 BTC—a $100 million fortune sitting in plain sight on the blockchain, yet currently out of reach for its rightful owners.







