Coldcard Hardware Wallet Losses Approach $130 Million as Galaxy Flags Ongoing Multi-Attacker Exploit
Galaxy Research estimates up to 2,055 BTC stolen from Coldcard wallets due to a long-standing firmware entropy flaw, with at least 15 attackers and funds still at risk.
- Galaxy Research has high confidence that 1,596 BTC (over $100 million) was stolen from roughly 7,300 addresses across three confirmed attack waves plus 14 smaller incidents.
- Including a suspected fourth wave would raise the total to about 2,055 BTC, or roughly $130 million.
- At least 15 separate attackers are now exploiting the vulnerability; 90% of stolen coins have not moved.
- Coinkite has released emergency firmware updates and urged users to migrate funds to new seeds immediately.
Losses tied to a firmware vulnerability in Coinkite’s Coldcard bitcoin hardware wallets have climbed past $100 million and could reach approximately $130 million, according to on-chain analysis from Galaxy Research.
In a detailed thread posted Monday, Galaxy said it has high confidence that 1,596 BTC was drained from about 7,300 addresses across three confirmed waves of attacks plus 14 smaller incidents. Adding a still-unconfirmed fourth wave would bring the total to roughly 2,055 BTC.
The firm later noted that at least 15 different attackers appear to be exploiting the same flaw, with new footprints identified through victim reports. The Block reported that Galaxy is sharing confirmed attacker and victim addresses with U.S. federal law enforcement, exchanges, and cyber investigators.
The root cause is a firmware integration error dating to a 2021 migration. Instead of drawing entropy from the device’s hardware true random-number generator, affected versions fell back to a software pseudo-random number generator. On older Mk2 and Mk3 models the effective search space shrank to roughly 40 bits; later models that mixed in secure-element entropy still reached only about 72 bits against a 128-bit target, according to Coinkite’s technical backgrounder and detailed analysis by Decrypt.
Coinkite has released emergency firmware updates for all affected models (Mk3, Mk4, Mk5 and Coldcard Q), destroyed remaining vulnerable inventory, and repeatedly urged users to move funds. CEO Rodolfo Novak wrote that the company “will have to earn back our users’ trust,” while stressing that existing seeds generated on vulnerable firmware are not repaired by the update and must be replaced.
Galaxy emphasized the attack remains ongoing and that roughly 90% of the stolen bitcoin has not yet moved. Users whose seeds were generated without sufficient dice entropy or a strong BIP-39 passphrase are advised to generate a fresh seed on updated or alternative hardware and migrate funds promptly.
Latest Content
- Coldcard Hardware Wallet Losses Approach $130 Million as Galaxy Flags Ongoing Multi-Attacker Exploit
- BlackRock Launches Two Tokenized Money Market Funds Aimed at Stablecoin Reserves
- Coldcard Firmware Flaw Drains Nearly $89 Million in Bitcoin From Over 4,500 Addresses
- The Agentic Economy: Kite Payment Layer & Bitget’s AI-native trading
- Shiny Coins #20 – Extreme Fear Meets Selective DeFi Heat as UNI Steals the Spotlight
Related
- Coldcard Firmware Flaw Drains Nearly $89 Million in Bitcoin From Over 4,500 Addresses A 2021 Coldcard wallet flaw led to a $89M Bitcoin drain from 4,500+ addresses. Galaxy Research reported 1,367 BTC stolen across three waves, with Coinkite urging users to migrate funds....
- Introducing Africa’s First Hardware Wallet: Cardware Wallet – A New Era of Secure Digital Asset Storage Officially launching as Africa’s first digital asset hardware wallet....
- Top Recommended Crypto Wallets of 2025 Which One is Right for You?...
- Corporate Bitcoin Holdings: Which companies hold the most Bitcoin? Analyzing major bitcoin adopters and their strategies....



