Coldcard Wallet Flaw Linked to $111M Bitcoin Theft; Researchers Flag 25+ Attack Patterns
AI Market Summary
Galaxy Research reports confirmed theft of at least 1,719 BTC (~$111m) tied to a Coldcard firmware vulnerability affecting post-17 Mar 2021 wallets, with potential losses exceeding $130m. Over 25 attack patterns across three waves suggest multiple threat actors and broader exposure than initially estimated. While Bitcoin's core network is unaffected, the incident can pressure near-term sentiment and reinforce wallet and custody risk premiums.
Impact level
● Medium
Affected assets
BTC/USDT+0.85%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
The Coldcard wallet exploit now appears significantly larger than initially believed. Investigators have confirmed that at least 1,719 Bitcoin (BTC)—about $111 million—has been stolen from affected users, according to Galaxy Research.
Galaxy Research said it is still reviewing additional suspicious cases and believes total losses likely exceed $130 million. If the currently unconfirmed cases are validated, overall theft could top 2,300 BTC.
The incident centers on a vulnerability tied to certain Coldcard wallets running firmware released after March 17, 2021. Researchers suspect the issue impacted seed security or seed generation. Because a seed functions as a Bitcoin wallet's master key, attackers who could recreate it were able to access funds without physically tampering with the device.
The firmware timing is a key detail: investigators reported no stolen coins from wallets created before March 17, 2021. They also identified more than 25 distinct attack patterns across three waves, pointing to the likelihood that multiple threat actors exploited the same weakness.
More than 250 victims have reported losses so far, though the number of impacted addresses could be considerably higher because individual users may have operated multiple wallets. Galaxy Research noted that not every Coldcard wallet was exposed, but said the Mk3, Mk4, Mk5, and Q models appeared vulnerable when running firmware released after March 17, 2021.
Galaxy Research traced the start of the exploit to July 30, when an attacker drained roughly 594 BTC—about $38 million—from around 500 wallets in a 15&25-minute window, sparking alarm across the Bitcoin community. The Bitcoin core network itself was not affected.
Final Summary: Galaxy Research reports three waves and more than 25 attack patterns. If pending cases are confirmed, total losses could exceed 2,300 BTC.