Coldcard wallet exploit drains 1,816 BTC in coordinated attack waves
Macro & Markets ·
Onchain tracking shows roughly $114 million in bitcoin removed from more than 5,200 Coldcard addresses, with the attacker's cluster still active.
Approximately 1,816 BTC, worth around $114 million, has been drained across more than 5,200 affected addresses tied to Coldcard hardware wallets, according to figures shared on X. Confirmed waves 1 through 3 account for 1,367.05 BTC, or about $88.60 million, of that total. A fourth pattern-matched wave has added another 388.93 BTC across 462 likely victims, though the connected cluster behind that wave has not yet been fully identified from onchain data.
The exploit's scale places it among the larger hardware-wallet incidents tracked this cycle, with cryptopotato.com reporting the losses have topped $100 million and noting that the stolen BTC may be difficult for the attacker to spend given how closely the funds are being monitored. Separate analysis cited by theblock.co put the potential losses as high as $130 million across multiple waves of attacks, a figure attributed to Galaxy Research.
Despite the size of the theft, the attacker has not moved the stolen funds onward so far. Other accounts of the incident put the share of unmoved funds at around 90 percent, suggesting the perpetrator is holding rather than attempting to launder or liquidate the bitcoin, possibly due to the difficulty of doing so undetected while blockchain monitoring and law enforcement scrutiny continue.
The cluster tied to the exploit remains active, with a transaction recorded as recently as minutes before the latest update, indicating the drain may not be finished. Coldcard users have separately been urged to migrate funds immediately as a precaution.
What remains unresolved is the exact mechanism behind the exploit, the full scope of the fourth wave once its cluster is mapped, and whether the final loss figure will settle closer to the $114 million currently tallied or the $130 million estimate cited by Galaxy Research. Whether and when the attacker attempts to move or launder the unmoved funds is also unknown.