The Colcard exploit appears to be much larger than first thought. This is because investigators have now confirmed that at least 1,719 Bitcoin [BTC], or about $111 million, has been stolen from victims of the Coldcard exploit.


In fact, according to Galaxy Research,
We have many more coins we are vetting for confirmation – we think total losses likely exceed $130m.
So, if the suspicious but unconfirmed cases on their current list turn out to be confirmed, the total might surpass 2,300 Bitcoin.


How did this attack take place in the first place?
For context, the incident involved a flaw in some Coldcard wallets using firmware released after 17th March 2021. The flaw may have affected wallet-seed security or generation.
Since the seed served as a Bitcoin [BTC] wallet’s master key, attackers who managed to recreate it were able to access the money without the Coldcard being physically compromised.


The firmware release date mattered because investigators found no stolen coins from wallets created before then. They identified over 25 attack patterns across three waves. This suggested multiple threat actors exploited the vulnerability.


How widespread was the Coldcard exploit?
So far, over 250 victims have reported losses. However, the number of affected addresses may be much higher. A single victim could have used several wallets.
Galaxy Research said that not every Coldcard wallet faced exposure. However, Mk3, Mk4, Mk5, and Q models appeared vulnerable. Those models ran firmware released after 17th March 2021.
For context, the Coldcard exploit started on 30th July.
An attacker drained approximately 594 BTC, worth $38 million, from 500 wallets within 15 to 25 minutes.
The attack created concern across the Bitcoin community. Even so, Bitcoin’s core network remained unaffected.
Final Summary
- Galaxy Research has discovered over 25 attack patterns in three waves.
- If the current list turns out to be confirmed, the total losses might surpass 2,300 Bitcoin.





Be the first to comment