Coldcard Exploit Continues Draining Wallets as Theft Tally Reaches $88 Million
Galaxy Research tracks ongoing theft campaign targeting Coldcard hardware wallets, with losses now hitting approximately $88.6 million across 4,585 addresses after a third wave of attacks drained an additional 207.73 BTC.
Theft Campaign Accelerates Against Compromised Coldcard Devices
An active theft campaign targeting Coldcard hardware wallets has now resulted in approximately $88.6 million in stolen Bitcoin, according to research firm Galaxy Research. The attackers have successfully emptied around 1,367 BTC across 4,585 separate addresses in three documented waves of thefts. Galaxy Research’s head of research Alex Thorn warned Saturday that the attack remains ongoing and urged all Coldcard users holding single-signature funds to move their Bitcoin immediately, describing the exploitation as deliberate, programmatic, and likely orchestrated using large language models.
March 2021 Firmware Error Left Private Keys Predictable
The vulnerability stems from a firmware flaw in Coldcard devices manufactured by Coinkite in March 2021. The faulty firmware generated seed phrases—the randomized strings that create private keys—with insufficient entropy, making the resulting private keys guessable to attackers. Thorn cautioned that every single-signature Coldcard address created after the March 2021 firmware update will eventually be drained, as the weakness in key generation cannot be remedied retroactively. Galaxy Research flagged approximately 600 suspected attacker addresses to federal investigators and compliance firms, with assistance from victims who shared transaction details to help map the on-chain theft patterns.
Years of Dormancy Before Attack Awakens
A striking aspect of the theft campaign: the compromised funds had sat untouched in victim wallets for an average of 3.18 years before being drained, indicating the breach remained undetected since the 2021 firmware error. The stolen Bitcoin currently remains parked in attacker-controlled addresses and has not been moved, preserving the transaction trail for investigators. The situation has triggered an unusual reversal in the crypto industry, with panicked users moving their Bitcoin away from self-custody addresses and onto centralized exchanges like Coinbase and Binance—an inversion of the traditional “not your keys, not your coins” ethos that normally drives toward self-custody adoption.
Source: Galaxy Research, via Decrypt. Not financial advice.