Red Coldcard logo displayed in bold lettering against a plain black background.
TECHNOLOGY

Coldcard Bitcoin Theft Exceeds $100M

Image credit: Brandfetch

Confirmed losses linked to the Coldcard wallet vulnerability have exceeded $100 million, with Galaxy Research tracing 1,596 BTC across about 7,300 affected addresses.

The total covers three confirmed major attack waves and 14 smaller incidents. A suspected fourth wave remains under review and could increase estimated losses to 2,055 BTC, worth about $130 million.

Reports From 73 Victims Confirm 1,596 BTC in Losses 

Galaxy received reports from 73 victims, allowing researchers to confirm the first three major sweeps and connect additional transaction clusters to wallets generated with vulnerable Coldcard firmware.

The opening attack on July 30 removed 1,082.65 BTC from 1,196 addresses in 41 minutes. Later sweeps targeted wallets with smaller balances and used different transaction structures, increasing confirmed losses by more than 500 BTC.

Galaxy said each major wave appeared internally consistent with a single operator. Researchers have not determined whether one attacker controlled all three waves or whether multiple parties exploited the vulnerability.

Suspected Fourth Sweep Could Raise Losses to $130M 

Galaxy has excluded the fourth transaction cluster from its confirmed total because it has not received enough direct reports from affected users.

Including that cluster would increase estimated losses to about 2,055 BTC, worth approximately $130 million.

Around 90% of the Bitcoin linked to the confirmed theft remained unmoved when Galaxy published its findings. Researchers have shared suspected attacker and victim addresses with federal law enforcement agencies, crypto exchanges and blockchain investigation companies.

Users Must Replace Vulnerable Seeds Despite Firmware Fixes 

The vulnerability dates to a March 2021 firmware change that caused impacted Coldcard devices to use a deterministic software fallback during recovery-seed generation instead of the intended hardware random-number generator.

Seeds generated on affected Mk2 and Mk3 firmware may have contained about 40 bits of effective entropy. Some Mk4, Mk5 and Q seeds received additional secure-element randomness but may still have contained about 72 bits rather than the intended 128 bits.

Coinkite has released fixed firmware for all affected models. Installing the updates protects future seed generation but cannot strengthen recovery phrases created under vulnerable firmware.

Affected users must generate new seeds on fixed firmware and transfer their Bitcoin to fresh addresses. The confirmed total may increase as more victims report losses and Galaxy continues reviewing the suspected fourth wave.

More For You

Explore More News