A security crisis centered on Coldcard hardware wallets is deepening at an alarming pace. Losses tied to the exploits are now approaching $114 million, small Bitcoin transfers have surged to levels not seen since the immediate aftermath of the FTX collapse, and researchers at Galaxy Research have flagged what they believe is a likely fourth wave of thefts. The convergence of those three data points paints a picture that is difficult to dismiss as coincidence — and suggests the full scope of the damage may still be unfolding.

A Hardware Wallet Breach with Systemic Echoes

Coldcard occupies a specific and trusted niche in the Bitcoin ecosystem. Unlike exchange-based custody or software wallets, hardware wallets represent the gold standard of self-custody for retail and technically sophisticated users alike. The premise is simple and powerful: private keys never leave the device, making remote compromise theoretically impossible. When losses associated with a hardware wallet brand approach nine figures, it does not just undermine confidence in one product — it raises questions about the security model of self-custody itself. That reputational damage may prove harder to quantify than the $114 million already attributed to the exploits.

The Small Transfer Signal Is Not Background Noise

On-chain analysts have learned over the years to read small Bitcoin transfer volumes as a behavioral barometer. When users move amounts under 1 BTC in rapid succession, it typically reflects one of two scenarios: panicked retail holders liquidating or relocating funds, or victims of a theft or security incident attempting to salvage whatever remains in compromised wallets. The current spike brings those sub-1 BTC transfer counts to levels last recorded in the days immediately following the FTX collapse in November 2022 — a moment of acute, industry-wide fear that triggered one of the largest self-custody migrations in Bitcoin's history. The echo is striking. Back then, users were fleeing centralized exchange risk. Now, the elevated activity appears to reflect a different but equally visceral anxiety: that the devices they fled to may themselves have been compromised.

Galaxy Research Raises the Alarm on a Fourth Wave

The involvement of Galaxy Research in tracking the theft progression adds institutional weight to what might otherwise be dismissed as fragmented incident reports. The firm has flagged a likely fourth wave of thefts — a phrase that implies an organized or methodical pattern rather than isolated opportunistic attacks. Multiple waves suggest either a persistent vulnerability that has not been fully patched or disclosed, a coordinated actor systematically working through a database of compromised credentials or seed phrases, or some combination of both. The distinction matters for victims and for the broader market: a patched, contained vulnerability is a crisis with a defined boundary; an ongoing, multi-wave exploitation pattern is something considerably more dangerous.

What the Attacker Profile Might Tell Us

The wave structure of the thefts deserves particular scrutiny. Supply chain attacks on hardware wallets — where devices are compromised before reaching end users — tend to produce a single, relatively discrete wave of victims corresponding to a specific production batch or distribution channel. Multi-wave patterns are more consistent with a software or firmware vulnerability exploited over time, a social engineering campaign, or a leaked dataset of wallet configurations that is being monetized incrementally. None of these scenarios is comforting, but they carry different implications for how many additional users remain at risk and whether any defensive action is still available to them.

Self-Custody's Stress Test

The timing of this crisis is particularly pointed. Bitcoin has experienced sustained institutional inflows over the past several years, and retail adoption of self-custody solutions accelerated sharply after the FTX implosion. The argument for holding your own keys — rather than entrusting assets to an exchange or custodian — has never been more mainstream. A near-$114 million loss event tied specifically to a leading self-custody device creates a genuine educational and psychological setback for that narrative. It does not invalidate self-custody as a practice, but it does demand a more nuanced conversation about what "secure self-custody" actually requires: verified firmware, purchase from authenticated sources, and ongoing threat monitoring rather than a set-and-forget assumption of safety.

What This Means Going Forward

The Coldcard situation is not yet a closed chapter. With Galaxy Research warning of a fourth theft wave and the total loss figure still climbing toward $114 million, users who hold Bitcoin on any hardware wallet — not just Coldcard — should treat this moment as a prompt for immediate security review. Moving funds to a freshly generated wallet on a verified, uncompromised device is a prudent precaution when a hardware security incident of this magnitude is actively evolving. The spike in small Bitcoin transfers suggests many users are already acting on that instinct. The question is whether the response is coming fast enough to stay ahead of the next wave.

Written by the editorial team — independent journalism powered by Bitcoin News.