Coldcard bitcoin theft surges to $88m as attackers keep draining hardware wallets

8 минут чтения

Coldcard Bitcoin Theft Surges to $88 Million as Attackers Keep Draining Wallets

The large-scale theft of Bitcoin from compromised Coldcard hardware wallets is still unfolding, and analysts now estimate that roughly 88 million dollars’ worth of BTC has been siphoned off-an amount they warn is likely to keep rising until every exposed wallet is emptied.

According to an updated analysis from Galaxy Research, investigators have identified a third major wave of thefts targeting Coldcard users. In this latest phase alone, attackers extracted 207.73 BTC, pushing total observed losses to around 1,367 BTC-approximately 88.6 million dollars at current prices-spread across 4,585 separate Bitcoin addresses.

Researchers describe the exploit as active and ongoing, not a historical incident that has been contained. Their assessment is blunt: any Coldcard wallet that remains vulnerable is expected to be drained eventually if users do not act. In particular, Galaxy urges anyone storing funds on a Coldcard in a single-signature configuration to move those coins immediately to a secure setup that is confirmed not to be affected.

To support law enforcement and industry response, Galaxy says it has identified and flagged roughly 600 Bitcoin addresses believed to be controlled by the attackers. Those addresses have been shared with federal investigative agencies, compliance and monitoring firms, as well as specialist cybercrime investigators across the crypto sector. This mapping effort relied heavily on victims who volunteered transaction data, allowing analysts to trace on-chain flows and uncover repeating behavioral and technical patterns associated with the thefts.

How the Coldcard Exploit Fits Into the Hardware Wallet Landscape

Coldcard has long been marketed as a security-focused, Bitcoin-only hardware wallet aimed at power users. Its reputation rested on strong physical security, air-gapped signing workflows, and open documentation that appealed to technically sophisticated holders. The scale of this exploit therefore lands as a shock for many who deliberately chose Coldcard to avoid software wallet risks or custodial exposure.

While complete technical details of all compromised setups have not been fully unified into a single public narrative, the emerging picture is that this is not a random spray of phishing victims but a systematic, targeted drain of wallets with specific characteristics. The fact that the attackers are moving in distinct “waves” suggests an organized campaign rather than isolated opportunistic hacks.

Why Single-Signature Setups Are in the Crosshairs

Galaxy’s warning specifically singles out single-signature Coldcard wallets. In a single-signature (single-sig) arrangement, one private key alone is sufficient to authorize a transaction. That makes the wallet easier to use, but it also means that if that one key-or the process that generates or handles it-is compromised, there is no additional safeguard.

In contrast, a multi-signature (multi-sig) setup requires multiple keys to sign off on any spend. Even if one device or seed phrase is exposed, an attacker still cannot move funds without access to the additional keys. This is why security professionals often recommend multi-sig for large, long-term Bitcoin holdings.

The pattern of thefts implies that the attackers either gained access to seed phrases, compromised the signing environment, or exploited a vulnerability that effectively gave them the same power as the wallet owner in single-sig configurations. That is enough to silently empty wallets, sometimes long after users believed their setups were safe.

The “Waves” of Attacks: What That Tells Us

The description of a third wave of thefts is critical. Rather than continuously draining every known vulnerable wallet at once, the attackers appear to be working in stages, periodically sweeping targeted addresses. This could indicate that:

– They are batching operations to reduce operational risk and traceability.
– They are refining their target list over time as more data becomes available.
– They may be waiting for funds to accumulate on some addresses before performing another large sweep.

Each successive wave both expands the total number of drained wallets and confirms that the attackers still retain effective access to additional vulnerable keys or signing flows. That is why researchers insist that users should treat this as a current, active threat-not a past incident.

Law Enforcement and Industry Response

By tagging approximately 600 suspected attacker-controlled addresses and distributing that intelligence to investigative and compliance teams, Galaxy and other analysts are attempting to cut off the thieves’ ability to safely cash out. Centralized exchanges, custodial services, OTC desks, and on- and off-ramp providers can leverage these address lists to flag suspicious deposits or withdrawals and potentially freeze funds before they are converted to fiat or other assets.

However, Bitcoin itself is permissionless: an attacker can still move stolen coins between self-custodied wallets indefinitely. On-chain monitoring can track these flows and build a detailed forensic trail, but real-world enforcement depends on points where stolen assets interface with regulated platforms or services tied to identities.

What Coldcard Users Should Do Right Now

For holders who have ever used a Coldcard-especially in single-signature mode-the situation calls for immediate and careful action:

1. Assume risk if your setup matches any known vulnerable pattern. If analysts or security experts have indicated that a certain firmware version, seed generation method, or configuration is at risk and you used that setup, treat your wallet as compromised until proven otherwise.

2. Move funds to a new, clean wallet.
– Create a new wallet using a device and process that is confirmed not to be affected.
– Generate a brand-new seed phrase; do not reuse any existing seed.
– Consider using a multi-sig configuration, ideally with keys generated on different hardware devices.

3. Use a secure environment during migration.
– Avoid installing unverified software or firmware during this transition.
– Perform the operation on a trusted computer and network, minimizing exposure to malware or remote access tools.

4. Verify addresses carefully.
– Confirm destination addresses on the hardware wallet screen itself, not just on the computer display.
– For large sums, conduct a small test transaction first, then move the bulk only after confirming it arrived as expected.

5. Document everything.
– Keep records of outgoing transactions from the potentially compromised wallet.
– These details may be useful if you later need to assist investigators or auditors in tracing events.

Lessons for Long-Term Bitcoin Security

The Coldcard exploit underscores several broader lessons for serious Bitcoin holders:

Hardware wallets are not invincible. Even devices designed for hardcore security can be undermined by flawed processes, vulnerabilities in firmware, supply-chain issues, or user misconfigurations.

Seed generation is critical. If the random number generation or seed creation process is ever compromised-by bad firmware, tampered devices, or malicious tools-every wallet derived from that seed is effectively doomed, even if it appears to function normally at first.

Defense in depth matters. Multi-sig, geographically separated backups, independent devices from different vendors, and rigorous operational hygiene together sharply reduce single points of failure.

Regular security reviews are essential. Treat your Bitcoin storage like an evolving security system, not a one-time setup. As new research emerges or vulnerabilities are disclosed, revisit your setup and be prepared to rotate keys, change devices, or adjust your architecture.

The Human Side: Delayed Realization of Loss

One particularly painful aspect of this type of exploit is that victims may not realize their funds are at risk until long after the initial compromise. Because Bitcoin wallets can sit untouched for months or years, owners sometimes only learn about the issue when they finally go to move coins-only to discover the wallet has been drained in a past wave.

This time delay complicates both emotional and legal outcomes. Victims may have no immediate indication of when or how the compromise took place, making it hard to pinpoint the responsible party or to argue about liability. It also reinforces why proactive action-moving funds before any personal signs of trouble-is so heavily emphasized by investigators.

Implications for the Hardware Wallet Industry

The ongoing Coldcard thefts will likely have ripple effects across the hardware wallet ecosystem:

Greater scrutiny of firmware and supply chains. Users and institutions may demand more transparent build processes, reproducible firmware, and stronger verification that devices are not tampered with before delivery.

Increased demand for multi-sig solutions. Custodians, family offices, and high-net-worth individuals may move away from single-device, single-sig architectures in favor of distributed key models that can survive the compromise of one component.

Heightened expectations of incident response. When vulnerabilities lead to large losses, users will increasingly expect rapid public communication, clear migration guidance, and collaboration with analysts and law enforcement.

How Individual Users Can Raise Their Security Bar

Even without deep technical expertise, bitcoin holders can take practical steps to substantially reduce the risk of catastrophic loss:

Segment your holdings. Keep only what you need for near-term spending in easily accessible wallets. Place long-term holdings in more complex, hardened setups such as multi-sig.

Diversify devices and vendors. If you use multi-sig, consider mixing hardware from different manufacturers so that a single vendor exploit cannot empty your entire treasury.

Stay informed. Periodically review security advisories from wallet makers and independent researchers. If you rely on a particular device to secure significant value, treat ongoing security awareness as part of the cost of holding that asset.

Test your recovery procedures. Ensure you actually can restore from backups, and consider rehearsing recovery on a small account before trusting a process with your entire balance.

The Bottom Line

The expanding Coldcard exploit is not just another isolated hack; it is a live, active campaign that has already stripped around 1,367 BTC-roughly 88.6 million dollars-from thousands of addresses and continues to claim new victims in waves. Analysts and investigators are mapping attacker addresses and sharing intelligence, but the most decisive protection for users remains self-initiated: move any at-risk funds to secure, uncompromised setups without delay, and treat wallet security as an ongoing discipline rather than a one-time task.