Key facts
- At least 15 attackers exploited a Coldcard vulnerability, according to Galaxy Digital.
- Estimated losses from the exploit have reached $100 million, with a potential for $130 million.
- Dragonfly partner suggested AI hardening costing around $2 could have prevented the exploit.
- A firmware bug in Coldcard's private key setup may have contributed to the vulnerability.
- The exploit reignited debates about the security of cold storage wallets.
At least 15 attackers have exploited a vulnerability in the Coldcard hardware wallet, leading to estimated losses of $100 million across three confirmed attack waves, with a potential for total losses to reach $130 million. Galaxy Digital's head of research, Alex Thorn, stated that new attackers were identified through victim reports, some of which involved different exploit methods than previously understood.
One victim's report of less than 1 BTC stolen helped Galaxy Digital label new attackers, leading to the discovery of an attack that siphoned 12 BTC from 126 addresses. The ongoing incident has renewed discussions about the security of cold storage solutions and the risks associated with self-custody of Bitcoin.
Haseeb Qureshi, managing partner at Dragonfly, suggested that the exploit could have been prevented with approximately $2 worth of AI hardening. This comment followed social media reports indicating that some AI models could rediscover the vulnerability in under 20 minutes. However, Tatsapat Saerejittima, data lead at crypto analytics platform Tokenomist, expressed skepticism, noting that claims of AI finding the vulnerability quickly likely involved the code being publicly available and lacked rigorous testing methodology.
Francesco, co-founder of crypto research firm Castle Labs, indicated that while AI is accelerating the discovery of cryptocurrency vulnerabilities, a potential role for Coldcard's specific private key setup was also considered. He noted that Coldcard used a lower level of private key entropy (40 bits) compared to the standard 128 bits used by other wallets, a result of a firmware bug, which may have facilitated the exploit. Francesco anticipates that the cost and speed of discovering such vulnerabilities will continue to decrease as AI capabilities advance.