All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

At least 15 attackers exploited Coldcard vulnerability, Galaxy Digital says

Created at 4 Aug · 2:46 PM1 source↑ Market-relevant
IN SHORT

Galaxy Digital reported that at least 15 attackers exploited a Coldcard vulnerability, with estimated losses reaching $100 million across three confirmed attack waves. Dragonfly partner suggested AI hardening could have prevented the exploit.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

15attackers exploited Coldcard vulnerability
$100 millionestimated losses from Coldcard exploit
3confirmed attack waves
$130 millionpotential total losses
$2cost of AI hardening to prevent exploit
12 BTCstolen in one identified attack
126addresses affected in one identified attack
40 bitsprivate key entropy used by Coldcard
128 bitsstandard seed entropy for other wallets

Who's Involved

Galaxy Digital
reported on the Coldcard vulnerability and its exploitation
Alex Thorn
Head of Research at Galaxy Digital
Dragonfly
investment firm whose partner commented on AI hardening
Haseeb Qureshi
Managing Partner at Dragonfly
Tatsapat Saerejittima
Data Lead at Tokenomist
Francesco
Co-founder of Castle Labs

↳ Why This Matters

The Coldcard vulnerability highlights the evolving threat landscape in cryptocurrency security, where AI may accelerate the discovery of exploits. It raises questions about the adequacy of current security measures for hardware wallets and the potential for AI to both aid and compromise digital asset security.

Key facts

  • At least 15 attackers exploited a Coldcard vulnerability, according to Galaxy Digital.
  • Estimated losses from the exploit have reached $100 million, with a potential for $130 million.
  • Dragonfly partner suggested AI hardening costing around $2 could have prevented the exploit.
  • A firmware bug in Coldcard's private key setup may have contributed to the vulnerability.
  • The exploit reignited debates about the security of cold storage wallets.

At least 15 attackers have exploited a vulnerability in the Coldcard hardware wallet, leading to estimated losses of $100 million across three confirmed attack waves, with a potential for total losses to reach $130 million. Galaxy Digital's head of research, Alex Thorn, stated that new attackers were identified through victim reports, some of which involved different exploit methods than previously understood.

One victim's report of less than 1 BTC stolen helped Galaxy Digital label new attackers, leading to the discovery of an attack that siphoned 12 BTC from 126 addresses. The ongoing incident has renewed discussions about the security of cold storage solutions and the risks associated with self-custody of Bitcoin.

Haseeb Qureshi, managing partner at Dragonfly, suggested that the exploit could have been prevented with approximately $2 worth of AI hardening. This comment followed social media reports indicating that some AI models could rediscover the vulnerability in under 20 minutes. However, Tatsapat Saerejittima, data lead at crypto analytics platform Tokenomist, expressed skepticism, noting that claims of AI finding the vulnerability quickly likely involved the code being publicly available and lacked rigorous testing methodology.

Francesco, co-founder of crypto research firm Castle Labs, indicated that while AI is accelerating the discovery of cryptocurrency vulnerabilities, a potential role for Coldcard's specific private key setup was also considered. He noted that Coldcard used a lower level of private key entropy (40 bits) compared to the standard 128 bits used by other wallets, a result of a firmware bug, which may have facilitated the exploit. Francesco anticipates that the cost and speed of discovering such vulnerabilities will continue to decrease as AI capabilities advance.

Frequently asked questions

The Coldcard vulnerability relates to its private key setup, where a firmware bug resulted in a lower level of private key entropy than typically used by other wallets, potentially making it easier to exploit.

Estimated losses have reached $100 million across three confirmed attack waves, with a potential for total losses to approach $130 million.

Dragonfly's managing partner suggested that approximately $2 worth of AI hardening could have prevented the exploit, though others question the methodology behind claims of AI discovering the vulnerability rapidly.

Galaxy Digital reported that at least 15 different attackers have exploited the Coldcard vulnerability.

What Happens Next

01Further victim reports may reveal additional attackers or attack waves.
02Coldcard is expected to address the firmware bug and security concerns.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

At least 15 attackers exploited the Coldcard vulnerability, according to Galaxy Digital.
Galaxy Digital identified new attackers through victim reports, some with different exploit methods.
One victim's report led to the identification of a new attack siphoning 12 BTC from 126 addresses.
Estimated losses from the Coldcard exploit have grown to $100 million across three confirmed attack waves.
A suspected fourth wave could bring total losses to about $130 million in Bitcoin.
Dragonfly managing partner suggested that approximately $2 worth of AI hardening could have prevented the exploit.
Some social media reports claimed AI models rediscovered the vulnerability in under 20 minutes.
A crypto analytics platform lead stated AI likely did not discover the vulnerability before it was public, citing a lack of blind testing.

Sources

T1
At least 15 attackers exploited Coldcard vulnerability: GalaxyGalaxy said that at least 15 different attackers have exploited the Coldcard vulnerability, which may have been avoided with just $2 worth of AI hardening, according to Dragonfly’s managing partner.Cointelegraph

Related Stories

Coldcard Urges Users to Move Bitcoin Amid Ongoing Exploit
4 Aug · 11:00 AM
Coldcard Exploit Highlights Risks in Air-Gapped Bitcoin Wallets
3 Aug · 8:46 PM
Dormant Bitcoin Wallet Moves $31M Amid Coldcard Security Crisis
4 Aug · 4:56 AM
Boltz Pauses Service Amid AI-Assisted Hacking Attempts
4 Aug · 12:11 AM
Bitcoin nears $64,000 as Coldcard exploit fears recede
4 Aug · 5:26 AM