Multiple Attack Waves Exploit Coldcard Vulnerability, Inflicting Over $100M in Bitcoin Losses
Galaxy Digital research reveals at least 15 separate attackers have leveraged a Coldcard hardware wallet flaw, resulting in confirmed losses exceeding $100 million across three attack waves with a potential fourth wave still unfolding.
Widespread Exploitation: 15+ Attackers Target Coldcard Users
A major cryptocurrency vulnerability affecting Coldcard hardware wallets has enabled at least 15 separate attackers to steal funds, according to Galaxy Digital’s research team. The scope of the coordinated assault expanded as additional victim reports came to light, revealing attack patterns that had previously eluded detection. In a noteworthy discovery, investigators identified a completely distinct attack variation after examining a single victim’s report of a relatively modest theft of less than 1 Bitcoin. This secondary attack had successfully extracted approximately 12 Bitcoin from a network of 126 different wallet addresses, demonstrating the breadth of the vulnerability’s exploitation.
Losses Exceed $100 Million Across Multiple Waves
Galaxy Research has confirmed that the Coldcard vulnerability has resulted in documented losses totaling $100 million across three confirmed attack waves. The firm has also identified indicators of a potential fourth wave currently in progress, which could raise the total loss figure to approximately $130 million in Bitcoin. The multi-wave nature of these attacks has reignited substantial debate within the cryptocurrency community about the true security merits of hardware wallets and whether individual self-custody actually provides meaningful advantages over alternative asset storage approaches.
Technical Flaws and the Emerging AI Vulnerability Discovery Threat
Security analysis has uncovered that Coldcard devices operated with significantly lower private key entropy than industry standards, utilizing just 40 bits instead of the standard 128-bit seed phrases employed by competing wallet manufacturers. This cryptographic weakness, attributed to a firmware error, materially expanded the practical attack surface. The incident has also generated considerable discussion around artificial intelligence’s emerging capability to identify blockchain vulnerabilities. Some online participants claimed AI systems could reconstruct the vulnerability in minutes, though security researchers have expressed skepticism toward these assertions, noting that independent AI discovery prior to public disclosure remains unlikely. Industry observers have nevertheless acknowledged that advancing artificial intelligence capabilities are consistently reducing both the time required and economic cost associated with discovering cryptocurrency vulnerabilities. A security executive suggested that minimal computational hardening measures could have completely prevented the attack vector, while experts anticipate this trend will accelerate as AI technology becomes increasingly sophisticated and prevalent in security research.
The incident underscores that even widely-adopted hardware wallets carry meaningful security risks, compelling all cryptocurrency custodians to maintain vigilant practices and continually reassess their asset security strategies.
Source: Galaxy Digital, via Cointelegraph. Not financial advice.