Coldcard hardware wallet losses grow to $130 million
Galaxy Research said losses from an ongoing exploit of Coldcard hardware wallets have grown to roughly $130 million, or about 2,055 bitcoin, with at least 15 separate attackers now draining vulnerable devices. The flaw, which traces back to a March 2021 firmware weakness in how the wallets generated seed randomness, has been actively exploited since 30 July across multiple waves of attacks.
Coinkite, Coldcard's manufacturer, has acknowledged the vulnerability and released emergency firmware, while Galaxy has been supplying attacker and victim wallet addresses to law enforcement and exchanges. The exploit has also stirred long-dormant holdings: a wallet holding 500 bitcoin, worth about $31 million, moved for the first time in more than 12 years, one of several old wallets to empty out as owners shift funds to safety.
A years-old firmware bug undermining a wallet's core security promise, rather than a one-off phishing attack, is what is pushing holders back onto exchanges they had left for self-custody.