Bitcoin Security

Galaxy Estimates Coldcard Exploit May Have Stolen Up to 2,055 Bitcoin

Galaxy Research estimates that thefts linked to Coldcard hardware wallets have reached 1,596 Bitcoin across three waves, with potential losses rising to about 2,055 Bitcoin worth nearly $130 million if a fourth wave is confirmed. Around 90% of the stolen funds remain unmoved, while affected users are urged to migrate funds and generate new seeds. These allegations are reported by LBank News and crypto.news and are not officially confirmed.

Coldcard hardware wallet security breach and Bitcoin theft investigation visual representation
Image: crypto.news via LBank

Overview of Reported Coldcard Thefts

Recent intelligence coverage published by LBank News based on discoveries from crypto.news details that Galaxy Research has tracked multiple waves of security incidents linked to Coldcard hardware wallets. According to these public reports, analysts have identified that confirmed thefts have accumulated to 1,596 Bitcoin distributed across three distinct attack waves. Furthermore, researchers indicate that if a suspected fourth wave of malicious activity is fully verified, aggregate losses could expand to approximately 2,055 Bitcoin, which equates to nearly $130 million based on prevailing market valuations. These figures underline a significant ongoing security event affecting hardware wallet owners worldwide.

The investigative updates highlight that investigators have actively shared both confirmed attacker wallet addresses and victim destination addresses with various U.S. law enforcement agencies, cryptocurrency exchanges, and specialized cyber investigation groups. Despite the scale of the alleged thefts, market analysts note an encouraging operational detail in that approximately 90% of the stolen Bitcoin remains untouched on-chain. This retention of funds provides a crucial window for security monitors and platform operators to observe blockchain movements, although affected participants face immediate pressure to secure their remaining assets against potential secondary exploits.

Analysis of the Suspected Fourth Wave

Security analysts at Galaxy Research have pointed out that while three attack waves are firmly documented through empirical victim confirmation, a fourth wave remains in a suspected status due to a lack of sufficient direct reporting from affected wallet owners. The research organization explained that blockchain network activity and transaction topologies strongly suggest the existence of this fourth wave, which appears to be substantially orchestrated by a single primary operator. This operational pattern has granted investigators a medium-high degree of confidence in attributing the clustered transactions despite the current absence of complete victim verification.

Alex Thorn, who leads firmwide research at Galaxy, initially brought public attention to this emerging fourth wave after observing transaction fingerprints that mirrored previous attack structures. His ongoing estimates suggested hundreds of additional Bitcoin moving across numerous potential victim addresses, though the firm consistently emphasizes that raw blockchain heuristics alone cannot definitively establish victim consent or definitively isolate a single threat actor. As additional data trickles in from wallet owners and external investigative partners, researchers continue refining their address maps to better understand the full scope of the incident.

Root Cause Traceable to Firmware Changes

The underlying security failure originates from a historical software update introduced in March 2021, which affected seeds generated across multiple Coldcard models including Mk3, Mk4, Mk5, and Coldcard Q devices running vulnerable firmware versions. Technical disclosures reveal that during the integration of a new cryptographic library, the firmware inadvertently bypassed the intended hardware-backed true random number generator. Instead, the affected systems mistakenly relied upon a deterministic pseudo-random number generator provided by MicroPython during the critical seed creation phase.

Independent technical reviews conducted by external security teams, including engineering personnel from Block, corroborated these findings after examining the vulnerable firmware code paths. The investigations demonstrated that while the physical hardware random-number generator remained functional elsewhere in the device architecture, the routine responsible for creating wallet seeds invoked the deterministic fallback rather than hardware entropy. This flaw resulted in drastically reduced entropy levels across different models, compromising the cryptographic strength intended by the hardware architecture.

On-Chain Behavior and Attacker Tactics

Detailed blockchain forensics have unveiled specific tactical behaviors utilized by the threat actors during the exploitation campaigns. During the escalation of the suspected fourth wave, attack velocity surged markedly, with address sweeps accelerating to roughly 13.8 wallet clearances per Bitcoin block, representing a dramatic spike compared to the baseline rate observed prior to the disclosure. Furthermore, analysts observed that stolen funds were typically dispersed into newly generated recipient addresses rather than being funneled into a single centralized consolidation hub.

In addition to decentralized distribution patterns, some of the stolen cryptocurrency was routed through subsequent second-hop transactions, introducing layers of obfuscation that complicate traditional blockchain tracing efforts. While some observers previously pointed to the Bitcoin Replace-by-Fee mechanism as a potential narrow avenue for users to front-run unconfirmed theft transactions by attaching higher fees, market experts warn that this option offers very limited utility and provides no guarantee of successful asset recovery once miners begin processing the original transaction blocks.

Manufacturer Response and Remediation Guidance

In response to the vulnerability disclosure, device manufacturer Coinkite has taken decisive steps by releasing emergency firmware updates across all impacted product categories. These security patches include version 4.2.0 for legacy Mk2 and Mk3 units, version 5.6.0 for Mk4 and Mk5 models, version 1.5.0Q for Coldcard Q devices, alongside specialized Edge releases. Additionally, the manufacturer reported the complete physical destruction of all remaining inventory that contained vulnerable firmware versions to prevent any further distribution.

Despite the availability of software updates, technical specialists emphasize that applying a patch alone does not retroactively secure existing wallet seeds created under historical vulnerable firmware versions. Coinkite strongly urges all users of affected hardware to generate an entirely new, cryptographically secure seed phrase on a fully updated device, verify receiving addresses carefully, conduct minor test transactions, and transfer the bulk balance only after the successful settlement of test transfers. Users are also reminded that physical dice-roll methods remain unaffected.

Risk Intelligence Assessment and Next Actions

In conclusion, these developments highlight a severe hardware security crisis affecting Coldcard users worldwide, with confirmed and suspected losses scaling toward 2,055 Bitcoin based on media reporting from LBank News and crypto.news. These claims remain not officially confirmed by independent first-party regulatory authorities. The affected entity is Coinkite, and the affected user group comprises owners of Coldcard Mk2, Mk3, Mk4, Mk5, and Q devices running vulnerable historical firmware.

What changes now is that investigators have shared actionable attacker data with law enforcement and exchanges, while the manufacturer has destroyed vulnerable inventory and published emergency patches. The next action for every affected user is to immediately stop using legacy seed phrases, update device firmware, generate an entirely fresh seed on a patched device, and securely migrate all funds to a newly protected wallet address.

Cexvia conclusion

Conclusion and Operational Outlook

According to reporting by LBank News based on discovery data from crypto.news, Galaxy Research identified confirmed Coldcard related thefts reaching 1,596 Bitcoin across three waves, with a suspected fourth wave potentially pushing total losses to approximately 2,055 Bitcoin valued near $130 million. Investigators have shared related addresses with U.S. law enforcement, exchanges, and cyber groups, while 90% of stolen coins remain unmoved. These claims are reported by media and remain not officially confirmed.

Risk meaning
The reported hardware wallet vulnerability exposes critical systemic risks in cryptographic entropy generation across multiple device models, underlining the danger that firmware defects can silently weaken random number generation and compromise user seed phrases. This situation demonstrates that even established hardware security devices can harbor long-standing flaws stemming from historical code integration errors, threatening substantial user assets and prompting coordinated tracking by analytical firms and law enforcement agencies.
User action
Affected Coldcard users are strongly advised by investigators and manufacturers to generate entirely new wallet seeds on updated, patched firmware devices and promptly migrate their remaining funds to secure addresses. Users must recognize that updating firmware alone does not protect existing wallet seeds created under vulnerable versions, necessitating a complete seed replacement and secure test transactions before full fund transfers.
U.S. Law Enforcement