Coldcard Hardware Wallet Exploit Drains Over $100M as Attackers Target Outdated Devices

Glossy 3D Bitcoin coin with golden rim light on deep navy surface, sharp shadows and fractured reflections.

Firmware flaw triggers urgent Bitcoin scramble

A critical vulnerability in Coldcard hardware wallets has triggered a wave of Bitcoin thefts, with confirmed losses now exceeding $100 million.

The urgency is underscored by the pace and scale of the thefts: as of early this week, at least 1,596 BTC had been siphoned from approximately 7,300 addresses across three major attack waves. A possible fourth wave was identified on Monday, with Galaxy Research estimating that an additional 449 BTC were stolen from 709 addresses in a single sweep—raising total suspected losses to around $130 million at current prices.

Bitcoin’s price hovered near $63,800 in early U.S. trading hours on Tuesday, amplifying the dollar impact of each compromised wallet.

BTCUSD : Recent trajectory

At least 15 hackers identified in spree

Investigators have linked the ongoing Coldcard exploit to at least 15 distinct attackers, based on patterns observed by Galaxy Digital’s research team. New victim reports continue to surface; one recent case involving less than 1 BTC led researchers to uncover another attacker responsible for draining 12 BTC from 126 addresses. This evolving picture suggests a coordinated yet fragmented campaign rather than a single perpetrator dominating the thefts.

Most of the stolen Bitcoin—over 90%—remains unmoved on-chain, raising questions about whether attackers are waiting for law enforcement attention to subside or simply biding their time.

On paper, hardware wallets like Coldcard promise robust self-custody security; in practice, outdated firmware has proven to be a critical weak point for thousands of users. Galaxy Research has shared both attacker and victim addresses with U.S. federal law enforcement and major crypto exchanges in an attempt to halt further laundering of stolen funds.

Single-key wallets prove dangerously vulnerable

The vulnerability specifically targets wallets set up with only one private key—meaning no secondary approval is needed for transactions. This design choice left thousands exposed when combined with the flawed entropy (randomness) generation in certain firmware versions. According to decrypt.co, the root cause was a software fallback that generated wallet seeds using only 40 bits of entropy instead of the industry-standard 128 bits provided by a typical 12-word seed phrase. As a result, attackers could feasibly guess private keys for affected wallets.

However, not all Coldcard users are equally at risk: those who used the device’s manual dice-roll option (entering results from at least 50 dice rolls) are not impacted by this exploit.

Victim reports reveal new exploit patterns

Galaxy Research has received direct contact from at least 73 victims since the incident became public knowledge. These reports have been instrumental in mapping out attack waves and identifying new malicious actors targeting Coldcard users. The largest confirmed sweep occurred after July 30th and accounted for over $100 million in losses across three primary waves and fourteen smaller incidents.

Security firms have also documented an uptick in phishing campaigns riding on the chaos created by these thefts. Proofpoint detailed how attackers are sending spoofed Coldcard emails and directing users to cloned websites designed to harvest recovery phrases or install malware under the guise of “hardware audits.” Trezor and Foundation—two other hardware wallet makers—have issued warnings about these tactics and stressed that their own devices remain unaffected by this specific bug.

It’s unclear how many more victims may emerge as awareness spreads and more users check their balances or update their firmware. For now, Coldcard manufacturer Coinkite has released patched firmware and continues to advise all potentially affected customers to migrate funds immediately using newly generated seeds.

The Big Picture

  • As of June 2024, Coldcard wallet exploit losses have reached up to $130 million, affecting at least 7,300 addresses.
  • The vulnerability stems from firmware present since 2021, with at least 15 different attackers identified by Galaxy Research.
  • Owners of Mk3 wallets set up on firmware 4.0.1+ and Mk4/Mk5/Q on firmware below 5.6.0/1.5.0Q are urged to move funds immediately.

What could tip the balance

If a suspected fourth wave of Coldcard exploit attacks—identified by Galaxy Research and involving roughly 449 BTC taken from 709 addresses on Monday—is confirmed, total losses could immediately rise to about $130 million; however, the full extent of this fourth wave remains unclear as of now.