Coldcard hardware wallet exploit tops $100 million in confirmed losses
Security & Exploits ·
Analysts tracking the breach say 1,596 BTC has been drained from roughly 7,300 addresses across three confirmed attack waves plus 14 smaller incidents, with a possible fourth wave still unverified.
The tally, posted by Galaxy Research, reflects high-confidence figures for confirmed activity only; folding in suspected but unconfirmed incidents pushes the estimate to roughly 2,000 BTC, or about $130 million. Separately, Decrypt reported the potential loss figure nearing $114 million, underscoring how the total keeps shifting as new victim reports surface.
The first wave was spotted by engineers at Blocks and confirmed through victim reports; waves two and three emerged the same way, with confirmations still arriving. Most affected users show up in a single wave, though some appear in two. Separately, 73 individual victims have contacted intangiblecoins for tracing help, and their reports helped identify 14 additional smaller footprints that may represent multiple opportunistic attackers exploiting the same disclosed flaw rather than one coordinated actor.
A quoted update from Alex Thorn flags what looks like a fourth organized wave unfolding in real time, spanning blocks 960,778 to 960,792 over roughly 2.5 hours, with 218 transactions, 462 victim addresses, 216 new destination addresses, and 388.92748828 BTC moved. Every transaction traces to inputs predating the Coldcard firmware boundary, and the sweep rate — 13.8 per block versus a 0.3 baseline before the incident — is running about 45 times above normal. The pattern is largely one-to-one, with a single fresh destination per victim and almost no funneling into a shared collection address, though some funds have already moved to second-hop wallets. That structural match gives medium-high confidence this is a genuine continuation of the attack, even though no victim has yet confirmed inclusion, which is why the wave has not been added to the official total.
Confirmed attacker and victim addresses have been shared with U.S. federal law enforcement, exchanges, and compliance and cyber-investigation firms. Ninety percent of stolen coins remain unmoved, and all coins from the first three waves are untouched so far. The Block reported that Jameson Lopp has pointed to the exploit as evidence of practical limits in Bitcoin's self-custody security model, noting that AI tools are amplifying both attack techniques and defensive countermeasures.
What remains unresolved is whether the suspected fourth wave will be formally confirmed, how many additional opportunistic attackers may still be exploiting the vulnerability, and whether the 90 percent of unmoved coins can be secured before further transfers occur. Coldcard users uncertain about device safety are being urged to move funds to a custodian, exchange, or fresh seed, while victims are asked to share drained addresses and attacker transaction IDs to aid tracing and law enforcement reporting.