A vulnerability buried in Coldcard hardware wallet firmware has now been linked to the theft of at least 1,367.05 Bitcoin — worth approximately $88.6 million at the time Galaxy Research published its latest findings. Researchers have now catalogued three distinct suspected attack waves targeting addresses believed to have been generated by the compromised firmware, and the pattern shows no sign of resolution. For the Bitcoin self-custody community, this is one of the most consequential hardware wallet security events on record.
The third wave, identified most recently by Galaxy Research, extracted 207.7294 BTC on its own — a meaningful addition that brought the cumulative drain across 4,585 affected addresses to the current total. What makes the third wave particularly significant, according to researchers, is that it appears to employ different operational techniques than the prior two waves. That distinction matters: it suggests either a single sophisticated actor refining their approach to avoid detection, or potentially multiple threat actors exploiting the same underlying firmware weakness through separate campaigns. Either scenario is deeply troubling.
Coldcard wallets are manufactured by Coinkite and have long been regarded as among the most security-hardened consumer Bitcoin storage devices available. They are favored precisely by users who prioritize self-custody and distrust centralized exchanges — individuals who, in many cases, hold meaningful Bitcoin positions and rely on the device as their primary security perimeter. The irony of a hardware wallet known for its security culture becoming the vector for a nine-figure loss will not be lost on the broader community.
The mechanics of the exploit center on firmware-level address generation. When a Coldcard device runs vulnerable firmware, the Bitcoin addresses it produces may not be cryptographically sound in the way users expect — either the randomness used to derive private keys is compromised, the keys are predictable, or the derivation process itself is flawed in a way that allows an outside party to reconstruct wallet keys. Across 4,585 addresses, the pattern is consistent enough that Galaxy Research has been able to cluster the suspected victims and track fund movements on-chain, wave by wave.
The scale — $88.6 million spread across nearly 4,600 addresses — also challenges a common assumption about hardware wallet exploits: that they tend to be surgical, targeting a small number of high-value wallets. This event appears to be systematic and broad-based, suggesting the attacker or attackers may have been working from a list of deterministically derived keys, sweeping funds methodically rather than relying on social engineering or physical device compromise. That is a fundamentally different threat model, and one that hardware wallet manufacturers across the industry will need to confront head-on.
For users who generated addresses using Coldcard devices running the identified vulnerable firmware versions, the immediate priority is straightforward: move funds to addresses generated by a clean, verified, and up-to-date device or software wallet. The fact that Galaxy is still identifying new waves means the threat remains active, and addresses that have not yet been swept could still be at risk. Waiting for confirmation of a "final" wave before acting would be a mistake.
At the infrastructure level, this episode raises urgent questions about firmware audit standards across the hardware wallet category. Coinkite built Coldcard's reputation on open-source firmware and a rigorous security posture — the discovery of a flaw severe enough to enable $88.6 million in losses across multiple coordinated attack waves is a fundamental challenge to that reputation, regardless of how the vulnerability was introduced. Independent third-party audits, reproducible firmware builds, and clearer versioning communication to end users are no longer optional best practices; they are table stakes for any device that positions itself as a Bitcoin cold storage solution.
Galaxy Research's methodical wave-by-wave analysis represents exactly the kind of on-chain forensics the ecosystem needs more of. By clustering affected addresses and tracking fund flows, researchers can help victims understand their exposure and potentially assist law enforcement in following the money. But forensics, however valuable, is reactive. The harder work — building firmware pipelines rigorous enough that a vulnerability of this magnitude cannot go undetected long enough to enable three separate attack waves across 4,585 addresses — belongs to manufacturers, auditors, and the open-source contributor community working together before the next wallet is compromised.
Written by the editorial team — independent journalism powered by Bitcoin News.