Coldcard Hardware Wallet Hack Devastates 8,865 Addresses With 1,789 BTC Theft
Galaxy Research quantifies the Coldcard breach at 1,789 Bitcoin stolen from thousands of addresses, with the majority of funds remaining frozen in attacker wallets.
Scale of the Hardware Wallet Compromise
A comprehensive analysis by Galaxy Research reveals the extent of one of crypto’s largest hardware wallet security breaches. According to the firm’s latest assessment, attackers siphoned 1,789.28 Bitcoin from 8,865 separate addresses in what has become known as the Coldcard hack. At the time of the theft, these funds represented approximately $114.7 million in value.
The scope of individual losses underscores the severity of the exploit. Among 221 documented victim reports covering 790.72 Bitcoin—representing 44.2% of Galaxy’s total attribution—the median loss per account reached 1.04272 Bitcoin. This statistic carries particular significance: it indicates that more than half of all reported cases involved individual losses exceeding one full Bitcoin, suggesting many targets held substantial digital assets on the compromised hardware wallets.
Attacker Funds Remain Largely Immobilized
A critical finding from Galaxy Research shows that the majority of stolen Bitcoin has not entered circulation. As of the analysis, 1,561 Bitcoin—accounting for 87.3% of the total theft—sits dormant in addresses controlled by the attackers. These holdings, including all Bitcoin taken during the first three waves of attacks, remain visible on the blockchain in collection and staging addresses rather than being spent or moved to new locations.
However, funds stolen during subsequent attack phases have exhibited different patterns. Some Bitcoin has moved through mixing services like CoinJoin and peel chain transactions—technical methods designed to obfuscate fund origins and ownership trails on the blockchain. This activity suggests attackers are attempting to launder at least a portion of their gains through privacy-enhancing techniques.
Industry Response and Recovery Efforts
Galaxy Research has shared the identified attacker-controlled addresses with cryptocurrency exchanges, compliance-focused firms, and law enforcement agencies worldwide. This collaborative approach aims to intercept stolen funds if they surface on centralized platforms, where they could potentially be frozen through legal channels. The strategy leverages blockchain analysis transparency—a fundamental advantage of distributed ledger technology—against criminal actors seeking to profit from the compromise.
The Coldcard incident underscores persistent vulnerabilities in cryptocurrency hardware wallet security, affecting confidence across the entire digital asset ecosystem.
Source: Galaxy Research, via Cointelegraph. Not financial advice.