Coldcard exploit tops $100M as stolen haul reaches 1,596 BTC
AI Market Summary
Galaxy Research's investigation indicates the Coldcard-related compromise now exceeds 1,596 BTC (>"100M) across ~7,300 addresses, with suspected losses near 2,000 BTC. While most coins remain unspent, the scale highlights material custody and key-generation risk, likely increasing near-term sensitivity to self-custody practices, wallet-vendor scrutiny, and compliance monitoring of flagged addresses. Emergency firmware and seed-rotation guidance reduce future exposure but cannot remediate weak historical seeds.
Impact level
● High
Affected assets
BTC/USDT+0.55%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
A case that first looked like a contained hardware-wallet breach has expanded into a sweeping forensic probe, with the estimated damage repeatedly revised upward.
Early analysis tied the Coldcard exploit to 4,585 addresses across three theft waves, totaling about 1,367 BTC (roughly $88.6 million). Investigators later uncovered another 1,912 impacted addresses, adding 207.73 BTC, and noted that the stolen coins remained unspent. Galaxy Research said the on-chain behavior pointed to an operator focused on consolidating funds rather than quickly liquidating them.
The scope has since widened again. Confirmed losses now exceed 1,596 BTC—more than $100 million—spread across roughly 7,300 addresses. Galaxy Research also flagged 14 smaller related incidents, lifting suspected losses toward 2,000 BTC, or close to $130 million. The episode is being framed as one of the most significant custody-security failures affecting Bitcoin hardware wallets, prompting broader scrutiny of wallet resilience.
On-chain patterns reinforce the investigation
Blockchain forensics are clarifying how the stolen Bitcoin has been handled. The three confirmed waves remain the core of the case, while a fourth suspected wave could raise total losses to 2,055 BTC (around $130 million) if victims validate the link.
Fund flows have followed a notably consistent playbook. About 90% of the stolen BTC is still untouched, and coins moved in Wave 1, Wave 2, and Wave 3 remain parked at their receiving addresses. That inactivity has helped investigators map attacker-controlled wallets and surface additional connected addresses.
Separately, the newly identified smaller thefts suggest opportunistic actors may have taken advantage of similar conditions after the initial compromise. As attribution improves, investigators are sharing verified addresses with law enforcement, exchanges, and compliance firms to improve monitoring of any future movements and reduce off-ramp options.
Self-custody standards under the spotlight
The incident has also tested a long-held belief around Bitcoin self-custody. Investigators argue the issue is not self-custody itself, but the need for well-designed wallets and independent entropy generation. The findings reinforce user-protection practices such as multisig setups and stronger backup methods.
In response, Coinkite issued emergency firmware, paused shipments, and advised users to generate entirely new seeds before moving funds. Software updates, though, cannot fix weak seeds that were previously generated. Restoring confidence may hinge on transparent security reviews, verifiable randomness, and clearer industry standards.
Final Summary
The Coldcard exploit has surpassed $100 million in confirmed losses, making it one of the largest hardware-wallet security incidents in Bitcoin. The fallout is accelerating calls for tighter self-custody safeguards and more robust wallet security practices.