Coldcard exploit stole 1,778.84 BTC, with possible losses rising to 2,417 BTC

Galaxy Research said the Coldcard hardware wallet exploit has now been highly confirmed to have stolen 1,778.84 BTC, worth about $112.7 million, from more than 8,600 addresses after a March 2021 firmware flaw made some wallet seeds predictable. The firm said with high confidence that at least some attackers used AI models without cybersecurity safeguards to help discover the vulnerability and execute the thefts, citing open-source systems such as Kimi K3 as a likely example. Galaxy has directly contacted 190 victims and has not identified any new high-confidence attack waves after Aug. 6, although medium-confidence suspicious activity, including an unconfirmed fourth wave, could push total losses to 2,417.35 BTC, or about $153 million. The report said most of the confirmed stolen bitcoin, 1,531 BTC, remains unmoved in attacker-controlled addresses, while about 246 BTC has been transferred, with roughly 65% entering CoinJoin transactions and 35% moving onward on-chain, sometimes through peelchains. Galaxy said the breach now ranks twentieth among recorded crypto thefts by dollar value, between Multichain's $130 million loss in July 2023 and Harmony's Horizon bridge theft of $100 million in June 2022. It also said no theft transaction has been identified from a multisignature wallet, while providers such as Casa, Anchorwatch and Unchained reported stronger inflows or signups as users reassessed single-signature self-custody risk. Galaxy advises anyone still holding funds on a single-signature Coldcard wallet to move them to new addresses because updating firmware does not fix a seed that was generated on affected firmware.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.