The financial impact of the Coldcard hardware wallet vulnerability continues to grow, with Galaxy Research now estimating that attackers have stolen 1,596 bitcoin (BTC), worth more than $100 million, through a series of coordinated thefts. Researchers say the campaign is still active and warn that total losses could rise further if a suspected fourth wave of attacks is confirmed.

 

 

According to Galaxy Research, the confirmed figure is based on blockchain analysis and reports from affected users. Investigators say they have identified three large attack waves and 14 smaller incidents involving approximately 7,300 wallet addresses. The firm describes these findings as having “high confidence” but notes that the investigation remains ongoing and additional victims may still come forward.

Researchers are also monitoring a separate cluster of suspicious transactions that they believe may represent a fourth organised attack. That activity has not yet been confirmed through victim reports, so Galaxy has deliberately excluded it from its official loss estimate. If the additional activity proves to be part of the same campaign, the total amount stolen could increase to roughly 2,055 BTC, valued at around $130 million based on current market prices.

Unlike the earlier attacks, the suspected fourth wave was detected while it was still unfolding. Alex Thorn, Head of Research at Galaxy, said analysts observed hundreds of bitcoin transfers occurring within a short period, a pattern that differed significantly from normal network activity. Because many of the transactions remained unconfirmed for a period of time, some victims may have had a brief opportunity to recover their funds by using Bitcoin’s Replace-by-Fee (RBF) feature to submit competing transactions with higher fees before the attackers’ transfers were finalized.

Galaxy believes the campaign may also be expanding beyond a single threat actor. While each of the initial large-scale thefts appears to have been carried out by one operator, the smaller incidents suggest multiple attackers may now be exploiting the same publicly known weakness. The firm said 73 victims have already assisted the investigation by providing information that helped trace stolen funds.

One encouraging finding is that most of the stolen cryptocurrency has not yet been moved. Galaxy estimates that roughly 90% of the bitcoin taken remains in attacker-controlled addresses, with all coins stolen during the first three confirmed attack waves still sitting in wallets visible on the blockchain. Because the funds remain traceable, the company said it has shared hundreds of suspected attacker wallet addresses with US law enforcement agencies, cryptocurrency exchanges and blockchain investigation firms.

The incident has also reignited discussion about artificial intelligence and software security. Coinkite, the manufacturer of Coldcard, has suggested that attackers may have used AI to identify the firmware flaw within its open-source code, although the company stressed this is an assumption rather than a confirmed fact. Galaxy likewise said the automated nature of the thefts suggests large language models may have assisted the attackers, but it also described that assessment as an informed opinion rather than verified evidence.

Both Galaxy Research and Coinkite continue to urge users with potentially affected Coldcard wallets to migrate their bitcoin immediately. Researchers emphasize that installing updated firmware alone does not secure wallets created using vulnerable recovery seeds. Instead, users should generate an entirely new seed phrase on patched firmware and transfer their funds to the newly created wallet as soon as possible.

Leave a Reply