At least 15 attackers exploited Coldcard vulnerability: Galaxy
Source Entity
Cointelegraph by Zoltan Vardai

A critical vulnerability in Coldcard hardware wallets has resulted in over $130 million in Bitcoin losses across multiple attack waves. At least 15 different attackers have been identified, with 90% of the stolen funds currently remaining unmoved.
The Coldcard Security Crisis: A $130 Million Breach
The cryptocurrency ecosystem is currently grappling with a significant security breach involving Coldcard hardware wallets. According to reports from Galaxy Research and blockchain monitoring firms, this vulnerability has facilitated the theft of over $130 million in Bitcoin (BTC). The nature of this exploit is particularly concerning, as it targets hardware wallets, which are traditionally considered the gold standard for secure, offline digital asset storage.
Anatomy of the Attack
Data analysis reveals that the theft occurred in three major waves, supplemented by 14 smaller, opportunistic incidents. Investigators have confirmed that approximately 1,596 BTC were initially stolen from roughly 7,300 addresses. As investigations continue, Galaxy Research has identified a suspected fourth wave of attacks. If confirmed, this would bring the total volume of stolen assets to approximately 2,055 BTC, cementing this event as a major incident in the history of retail cryptocurrency security.
A Decentralized Network of Attackers
Unlike a singular breach on a centralized exchange, this incident involves a fractured group of perpetrators. Alex Thorn, head of research at Galaxy Digital, has confirmed that at least 15 different attackers have exploited this vulnerability. By analyzing victim reports—including one instance involving less than 1 BTC that led to the discovery of a larger 12 BTC theft across 126 addresses—researchers have been able to map the 'footprints' of these diverse bad actors.
The Role of Preventative Security
Perhaps the most striking aspect of this breach is the suggestion that it could have been mitigated with minimal investment. Dragonfly’s managing partner has noted that the vulnerability might have been avoided with as little as $2 worth of AI-based hardening. This highlights a growing tension in the industry between the convenience of hardware wallet manufacturing and the necessity of rigorous, forward-looking security protocols.
Broader Implications and Asset Status
Currently, blockchain-monitoring firms estimate that 90% of the stolen Bitcoin remains unmoved. This provides a glimmer of hope for potential recovery efforts, though it also creates a long-term 'overhang' on the market. The decentralized nature of these attacks makes attribution difficult, leaving the broader crypto-community to grapple with the reality that even 'offline' security solutions are susceptible to sophisticated, multi-vector exploitation.
Conclusion
This incident serves as a stark reminder of the evolving threat landscape facing Bitcoin holders. As attackers become more specialized and exploit vulnerabilities at scale, the reliance on hardware manufacturers to maintain flawless security updates becomes paramount. Future trends suggest that users must demand greater transparency in hardware auditing, while the industry may need to adopt advanced security hardening techniques to prevent similar catastrophic losses in the future.