Galaxy Research verifies $111M Coldcard theft, warns total could top $130M
Security & Exploits ·
The research group says it has high-confidence data on stolen funds but expects the final tally to climb well beyond current confirmed losses.
Galaxy Research has verified, with high confidence, that 1,719 BTC — approximately $111 million — has been drained from users through a security flaw tied to the Coldcard hardware wallet, according to wublockchain.xyz. The firm cautions that once outstanding claims are processed, cumulative losses tied to the incident could climb past $130 million.
Analysts at Galaxy have catalogued more than 25 distinct attack methods being used against affected devices, pointing to the involvement of several separate threat actors rather than a single coordinated group. So far, the team has logged reports from over 250 individuals claiming losses, and it warns that the confirmed BTC figure could nearly double to exceed 2,300 BTC if every pending report is substantiated.
The exposure is currently limited to specific Coldcard hardware lines — the Mk3, Mk4, Mk5, and Q models — with Galaxy stating it has found no indication that the underlying flaw extends to other signing devices or wallet software.
The fallout has prompted broader scrutiny of self-custody security practices. One related report frames the episode as renewing debate over private-key handling and the growing role of AI-assisted techniques in crypto-targeted attacks, a concern echoed in coverage from theblock.co. Separately, the scramble among holders to move funds off compromised devices has been linked to a surge in Bitcoin network activity, with active addresses reaching an eight-month high as users rushed to migrate wallets, per cryptopotato.com.
What remains unresolved is the full scope of the breach: Galaxy has not said how many of the 250-plus reported cases will ultimately be confirmed as legitimate losses, nor identified the root cause of the vulnerability or whether it has been patched. It is also unclear how many affected users have successfully moved funds to secure wallets, and whether additional device models could later be found exposed.