The scale of the Coldcard hardware wallet exploit is becoming sharply clear. Galaxy Research has now confirmed with high confidence that at least 1,719 BTC have been stolen across multiple user accounts, valuing the compromise at roughly $111 million at recent prices. But that number may not be the ceiling. Total losses, according to the research team’s latest assessment cited in the original report, are likely to surpass $130 million once all outstanding cases are verified.
More than 25 distinct attack patterns have been identified, and investigators now believe that multiple threat actors are actively exploiting the vulnerability. The number of victims is piling up; Galaxy confirmed it has received reports from over 250 individuals. If every case is ultimately confirmed, the total haul could climb past 2,300 BTC. For now, the only hardware known to be affected are Coldcard Mk3, Mk4, Mk5, and the Q model. There is no evidence that the bug has spread to other signing devices or wallets, and Galaxy has not indicated that any affiliated software or firmware outside of Coldcard’s ecosystem is compromised.
A self-custody nightmare
This incident hits at the very foundation of self-custody culture. Coldcard is widely considered one of the most secure Bitcoin hardware wallets, specifically designed for air-gapped, paranoid-grade storage. The fact that it has been cracked at this scale, with what appears to be a long-running exploitation window, will rattle confidence among users who have staked their entire net worth on it. It also complicates the already tense legislative conversation around self-custody protections in Washington. Just days before a crucial Senate vote on landmark crypto legislation—discussed in our coverage of how banks are attempting to reshape the bill—an exploit of this magnitude gives opponents of liberal self-custody rules a powerful new data point.
Hardware wallets have been sold as the ultimate defense against hacks, yet they remain vulnerable to supply chain attacks, firmware tampering, and physical side-channel exploits. In this case, the exact entry vector has not been publicly detailed by Coinkite or Galaxy, but the existence of so many distinct patterns suggests it was not a single bug. A misconfigured random number generator, a compromised supply chain component, or a flaw in the device’s communication protocols could all be at play. For users who lost funds, there is the added bitterness that Bitcoin’s immutability makes fund recovery virtually impossible.
What’s next for victims and the market
With over 250 victims already identified, legal and reputational consequences are mounting for Coinkite, the manufacturer of Coldcard. The firm has yet to release a detailed technical postmortem, and the market is waiting to see whether a patch is even feasible for existing hardware or if replacements are necessary. So far, only Coldcard’s own line appears infected, but the discovery of multiple independent attackers suggests the vulnerability may have been widely known in certain circles before it became public. That raises the uncomfortable possibility that the exploit was first discovered and traded privately, only becoming a headline after losses spiraled.
From an institutional perspective, this event will push funds and large holders toward scrutinizing their device choices more intensely. Multi-sig setups and custodian-based cold storage solutions may see renewed interest. The insurance question also re-emerges: most self-custody users carry zero coverage, while regulated custodians bundle insurance into their service. The $130 million-plus figure, though small compared to total Bitcoin market cap, is large enough to attract regulatory attention at a time when lawmakers are weighing how to classify and supervise wallet providers.
Uncertainty looms
Several unanswered questions make this a story that will develop further. Galaxy’s report does not clarify how the attackers managed to exfiltrate private keys or sign transactions without physical access to the devices. It is possible that the vulnerability allowed an attacker who gained temporary access—perhaps during shipping or through a compromised reseller—to later drain funds without ongoing access. The fact that over 25 patterns exist indicates that multiple techniques were employed, and it cannot be ruled out that some victims unknowingly used malicious firmware updates from unofficial sources.
The community is left to weigh whether the Coldcard brand can recover its reputation. Hardware wallet security is as much about trust as it is about cryptographic design. Once that trust is broken at a scale of thousands of coins, the road back is long. Meanwhile, other manufacturers will likely use this event to market their own devices as superior, and the broader lesson for the industry is clear: self-custody demands constant vigilance, and no single device should be treated as a magic shield.




Be the first to comment