Key Highlights
- Galaxy Research confirmed 1,719 BTC, worth approximately $111 million, has been stolen from Coldcard users, with total losses likely exceeding $130 million.
- The confirmed thefts span more than 25 attack patterns across three waves, with evidence suggesting multiple threat actors rather than a single attacker.
- The vulnerability currently appears limited to Coldcard Mk3, Mk4, Mk5, and Q devices running firmware released after March 17, 2021, while Coinkite has suspended automatic customer data deletion amid potential litigation.
Galaxy Research, a crypto and blockchain research firm, has confirmed that 1,719 bitcoin, valued at approximately $111 million, has been stolen from Coldcard hardware wallet users in an ongoing exploit.
In an X post on Friday, the firm stated that additional coins remain under review and that total losses are likely to exceed $130 million. Confirmation relies on victim reports and multiple corroborating details.
What was the exploit
A firmware bug introduced in a March 2021 update caused affected Coldcard devices to generate recovery seeds with insufficient randomness. Newer models produced roughly 72 bits of entropy instead of the expected 128 bits, while older Mk2 and Mk3 units generated even weaker seeds. As a result, the private keys could be reconstructed offline without physical access to the device.
Attackers precomputed these weak seeds and started transferring funds in coordinated waves beginning July 30. The theft has since evolved into a fragmented effort involving multiple independent actors.
Scope of confirmed losses
The confirmed figure of 1,719 BTC represents only those cases meeting a high-confidence threshold, typically established through multiple victim reports. Galaxy Research is tracking more than 25 separate attack patterns across what it describes as Waves 1, 2, and 3. The pattern of losses indicates involvement by multiple distinct threat actors rather than a single group.
None of the stolen coins were created on-chain prior to the March 17, 2021, release of the affected Coldcard firmware. This timeline aligns the losses with devices running firmware versions issued after that date.
Current evidence limits the vulnerability to specific Coldcard models: Mk3, Mk4, Mk5, and Q units operating on firmware released after March 17, 2021. Galaxy Research stated there is no evidence at this time that the bug affects other signing devices or wallets outside this set.
Victim reports and profile
The researcher operating under the handle @intangiblecoins has received reports from more than 250 victims. The volume of submissions has created a backlog, though the researcher has indicated an intention to respond to each report.
Galaxy Research described the confirmed loss profile across the three waves as consisting primarily of everyday bitcoin users rather than large holders. Cases are added to the confirmed set only when high confidence is established through cross-checked victim information.
Company response on data retention
Coinkite, the Canadian company that manufactures Coldcard devices, has suspended its automatic customer-data deletion policy. The change was disclosed in an August 6 blog post and is intended to preserve records for expected litigation arising from the firmware flaw.
Under Coinkite’s standard practice, customer records are automatically blanked after 120 days, with only an email address and country of residence retained. Customers could previously request accelerated deletion at any time after delivery.
That automated process is now on hold. The company stated that the suspension results from legal obligations connected to the security incident, including the need to retain records that may be relevant to ongoing and anticipated legal proceedings.
The firm has not released a complete list of attack vectors or a full accounting of unconfirmed amounts beyond the estimate that total losses likely exceed $130 million. No independent public audit of the full loss figure has been cited beyond the victim-report methodology described by Galaxy Research and the associated researcher.
Also Read: BTCPay Server Warns of Critical Flaw That Risks Bitcoin Funds
