Key facts
- Confirmed losses from Coldcard wallet exploits have surpassed $100 million.
- An estimated 1,596 BTC has been stolen from approximately 7,300 addresses.
- A potential fourth attack wave could raise total losses to $130 million.
- 90% of the stolen Bitcoin remains unmoved.
- The exploit is linked to a March 2021 firmware version with a predictable seed generation flaw.
- Coldcard manufacturer Coinkite has released emergency firmware and advised users to migrate funds.
Confirmed losses from Coldcard wallet exploits have surpassed $100 million, with approximately 1,596 Bitcoin (BTC) stolen from about 7,300 addresses across multiple attack waves. Galaxy Research identified a suspected fourth wave that could bring total losses to 2,055 BTC, worth about $130 million, though this estimate excludes unconfirmed victim reports.
Galaxy Research stated that 90% of the stolen Bitcoin remains unmoved, and attacker and victim addresses have been shared with US federal law enforcement, crypto exchanges, and cyber-investigation companies. The exploit is linked to a March 2021 firmware version that used a predictable seed generation method, allowing attackers to reproduce private keys offline. Coldcard manufacturer Coinkite has released emergency firmware and advised users to migrate their funds to a safe address.
Small Bitcoin holders moved coins at a rate not seen since the collapse of FTX, potentially due to the Coldcard breach. This outflow included significant transfers of less than 1 BTC, with daily active addresses rising sharply on July 31.
