Coldcard hardware wallet exploit confirmed at $130M+ in losses across 250+ victims and 1,719 BTC stolen via vulnerability.
Security & Exploits ·
Galaxy Research has confirmed that approximately 1,719 BTC, valued around $111 million, were stolen through a Coldcard hardware wallet vulnerability affecting multiple device versions. The research firm estimates total losses may exceed $130 million across more than 250 victims, with unverified cases potentially pushing the figure to 2,300 BTC if confirmed.
The vulnerability appears to enable coordinated exploitation across different threat actors—researchers are tracking over 25 distinct attack patterns affecting Coldcard Mk3, Mk4, Mk5, and Q series devices running firmware released after March 17, 2021. The stolen addresses correlate specifically to that firmware release date. Most victims are described as ordinary Bitcoin holders rather than major account holders.
Key unknowns remain around the nature of the underlying vulnerability itself, remediation steps users should take, and verification status of the pending cases that would determine whether losses truly reach the higher 2,300 BTC threshold. No evidence has emerged that the vulnerability extends to other signing devices or wallets.