A damaging series of coordinated thefts targeting users of the Coldcard hardware wallet has surpassed $100 million in confirmed losses, according to fresh analysis from Galaxy Research. Three distinct attack waves have now been verified, and investigators are actively scrutinizing what may be a fourth — one that, if confirmed, would push the total damage to an estimated $130 million. The findings represent one of the most significant hardware wallet compromises in Bitcoin's history, raising urgent questions about supply chain integrity, seed phrase handling, and the limits of cold storage security.
Three Waves, One Pattern
Galaxy Research's investigators have structured their findings around a wave model, each wave representing a discrete cluster of victim wallets, timing patterns, and on-chain fund movements that share enough forensic similarities to suggest coordinated or at least methodologically consistent attacks. Confirming three such waves at over $100 million in aggregate losses is significant not merely for the dollar figure, but for what it implies about the scope and duration of the operation. This was not a smash-and-grab event. It was extended, deliberate, and targeted at a device widely regarded as among the most secure consumer-grade Bitcoin storage solutions available.
What makes the situation especially striking from an on-chain perspective is that 90% of the stolen Bitcoin has not moved since the thefts occurred. That figure cuts in two directions simultaneously. On one hand, it suggests the perpetrators may be practicing patience — a well-known tactic among sophisticated crypto criminals who wait for investigative heat to dissipate before attempting to launder or liquidate stolen funds. On the other hand, it gives blockchain forensic teams and law enforcement an unusually clear picture of where the funds sit, even if they cannot yet seize them. The funds are, in effect, visible but untouchable — a frozen crime scene on a public ledger.
The Fourth Wave Question
The suspected fourth wave, still under examination by Galaxy Research at the time of reporting, carries implications that extend well beyond the incremental $30 million it might add to the tally. If confirmed, it would indicate that whatever vulnerability or method enabled the first three attacks remained exploitable — or that the perpetrators have access to a victim pipeline broad enough to sustain multiple campaigns over time. The difference between a one-time breach and a recurring attack architecture is enormous in terms of both remediation urgency and the potential number of users still at risk.
Coldcard wallets are manufactured by Coinkite and occupy a respected position in the self-custody ecosystem, favored particularly by technically sophisticated Bitcoin holders who prioritize security over convenience. The device runs open-source firmware, supports air-gapped signing, and has historically been considered resistant to remote attack. That reputation makes the confirmed losses all the more jarring — and all the more important to understand precisely. Whether this attack exploited the device's hardware, its software, its supply chain, or user-side operational security failures remains a critical open question that the Galaxy Research investigation appears to still be working through.
What the On-Chain Silence Tells Us
The fact that 90% of over $100 million in stolen Bitcoin sits dormant is an unusual forensic signature. Most opportunistic thefts see rapid fund movement — through mixers, cross-chain bridges, or centralized exchange deposits — as perpetrators race to obscure their trail. Here, the stillness suggests either extreme operational discipline, a coordinated decision to wait for a specific laundering window, or some external constraint on fund movement. It is also possible that a portion of the stolen Bitcoin is held in wallets that the perpetrators themselves can no longer access — a scenario that has occurred in past large-scale crypto heists where internal disputes or key loss complicated the exit.
For the broader Bitcoin self-custody community, the stillness of those funds offers little comfort. The loss event has already occurred. The 90% figure is forensically interesting but financially irrelevant to victims who cannot recover their holdings through blockchain observation alone. What matters now is attribution, legal process, and — most critically — understanding the attack vector so that other Coldcard users can assess their own exposure.
What This Means for Cold Storage Security
This investigation lands at a fraught moment for hardware wallet trust. The crypto industry has spent years urging users to move assets off exchanges and into self-custody following high-profile exchange failures. The implicit promise was that a reputable hardware wallet, properly used, represented a near-impenetrable layer of security. A confirmed $100 million-plus theft from Coldcard users — with a potential fourth wave still under review — complicates that narrative significantly.
That is not to say self-custody is broken. It is to say that the security assumptions underlying any hardware wallet system are only as strong as the weakest link in the chain — whether that is device firmware, supply chain verification, seed phrase storage, or user behavior at the point of wallet setup. Galaxy Research's wave-based framework suggests a systematic pattern rather than scattered individual errors, which points toward a vulnerability that may be replicable and scalable. Until the attack vector is fully identified and disclosed, users holding significant Bitcoin on any Coldcard device face an uncomfortable uncertainty. The investigation continues, the fourth wave looms, and $130 million hangs in the balance.
Written by the editorial team — independent journalism powered by Bitcoin News.