Massive Exploit Targets Coldcard Hardware Wallets, Potential Losses Exceed $130M

In a detailed security report released on August 7th, Galaxy Research disclosed a critical vulnerability in Coldcard hardware wallets, specialized devices for Bitcoin storage. The firm's analysis has confirmed with high certainty that the exploit has directly led to the theft of 1,719 BTC, valued at approximately $111 million. Researchers further warn that the total financial impact is likely to surpass $130 million.

Sophisticated and Multi-Sourced Attack Campaign

The incident stands out due to its complexity. Galaxy's technical team identified more than 25 distinct attack vectors used to leverage the vulnerability. This diversity strongly suggests that multiple independent threat actors discovered and exploited the flaw concurrently, rather than it being the work of a single group. This multi-pronged assault significantly amplified the scale and speed of the theft.

Growing Victim Count and Potential Scale

The research group has already collected reports from over 250 affected users, with many cases still under verification. Galaxy Research indicated that if all currently unconfirmed cases are validated, the total amount of stolen Bitcoin could exceed 2,300 coins. This would position the event as one of the most costly security breaches ever involving a hardware wallet.

Scope of Affected Devices Clarified

Amid the concerning findings, the report provided some clarity on the vulnerability's scope. There is currently no evidence that the security flaw impacts other hardware signing devices or software wallets outside the Coldcard Mk3, Mk4, Mk5, and Q model lines. This delineation offers some reassurance to users of other products, but it underscores the urgent need for owners of the affected models to immediately assess their security posture.

This exploit serves as a stark reminder of the persistent risks in cryptocurrency self-custody. While hardware wallets are often championed as the pinnacle of security, vulnerabilities in firmware, supply chain complexities, and operational hazards remain. For significant holdings, implementing a layered security strategy—such as multisignature setups and asset diversification across different solutions—continues to be a fundamental best practice.