The scale of the Coldcard hardware wallet exploit is becoming sharply clear. Galaxy Research has now confirmed with high confidence that at least 1,719 $BTC have been stolen across multiple user accounts, valuing the compromise at roughly $111 million at recent prices. But that number may not be the ceiling. Total losses, according to the research team’s latest assessment cited in the original report, are likely to surpass $130 million once all outstanding cases are verified.
More than 25 distinct attack patterns have been identified, and investigators now believe that multiple threat actors are actively exploiting the vulnerability. The number of victims is piling up; Galaxy confirmed it has received reports from over 250 individuals. If every case is ultimately confirmed, the total haul could climb past 2,300 $BTC. For now, the only hardware known to be affected are Coldcard Mk3, Mk4, Mk5, and the Q model. There is no evidence that the bug has spread to other signing devices or wallets, and Galaxy has not indicated that any affiliated software or firmware outside of Coldcard’s ecosystem is compromised.
A self-custody nightmare
This incident hits at the very foundation of self-custody culture. Coldcard is widely considered one of the most secure Bitcoin hardware wallets, specifically designed for air-gapped, paranoid-grade storage. The fact that it has been cracked at this scale, with what appears to be a long-running exploitation window, will rattle confidence among users who have staked their entire net worth on it. It also complicates the already tense legislative conversation around self-custody protections in Washington. Just days before a crucial Senate vote on landmark crypto legislation—discussed in our coverage of how banks are attempting to reshape the bill—an exploit of this magnitude gives opponents of liberal self-custody rules a powerful new data point.
blockchainreporter.net