Coldcard hardware wallet thefts have slowed, but cumulative losses may exceed $150M according to Galaxy Research analysis.
Security & Exploits ·
Galaxy Research has documented confirmed Coldcard seed-recreation thefts totaling more than 1,778 BTC (approximately $112 million), with a suspected fourth wave potentially pushing cumulative losses to 2,417 BTC. The exploit began on July 30 and proceeded through three major attack waves plus over 30 smaller clusters, yet no confirmed attacker activity has surfaced after August 6. Galaxy has directly interviewed more than 190 victims to verify losses and continues advising single-signature Coldcard holders to transfer funds to new addresses.
A 2021 firmware modification downgraded the device's seed generation from a hardware random-number generator to a software substitute, weakening cryptographic strength from 128 bits to as low as 40 bits. This allowed attackers to reconstruct seeds using only a device's serial number and clock data, then drain wallets without phishing, malware, or physical device access. The largest verified wave extracted roughly 1,083 BTC in moments; Footprint E, the biggest single owner-confirmed cluster, took approximately 210 BTC across multiple addresses.
Galaxy attributes the slowdown in attack activity to the possibility that vulnerable users have already migrated their holdings or had their funds fully depleted. Of the confirmed theft amount, approximately 1,531 BTC remains stationary in attacker-controlled addresses, while roughly 246 BTC has moved further—with 65 percent flowing into coinjoin transactions. Whether the underlying vulnerability remains exploitable or attackers have simply exhausted accessible targets remains unclear.