Coldcard bitcoin exploit drains $88m as attackers keep siphoning wallets

5 минут чтения

Coldcard Bitcoin exploit swells to $88 million as attackers keep siphoning wallets

The campaign to steal Bitcoin from compromised Coldcard hardware wallets is far from over. New on-chain analysis shows that the attackers are still actively draining funds, with total observed losses now approaching 1,367 BTC-roughly 88.6 million dollars at current prices-spread across 4,585 separate addresses.

Researchers at Galaxy Research reported over the weekend that they have detected a third distinct wave of thefts. In this latest surge alone, an additional 207.73 BTC was removed from victim wallets, confirming that whoever is behind the operation is systematically working through a large pool of vulnerable devices rather than performing a one-off smash-and-grab.

According to Galaxy, the exploit must be treated as ongoing, not historical. The firm warned that every Coldcard wallet affected by the vulnerability is at risk of being fully emptied sooner or later, even if it has not yet been touched. Their clearest recommendation: anyone holding Bitcoin in a single-signature Coldcard wallet that might be impacted should move those funds to a secure setup immediately.

To support law enforcement and compliance efforts, Galaxy says it has identified roughly 600 addresses believed to belong to the attackers. These addresses have been passed to federal investigators, blockchain analytics teams and other cybersecurity specialists. The researchers stressed that many of these connections were only possible thanks to victims who voluntarily shared transaction records, enabling analysts to piece together repeating on-chain patterns and link seemingly unrelated thefts to the same operation.

Although the full technical details of the exploit have not been made public in this excerpt, the scale and persistence of the thefts point to a method that allows the attackers to reliably reconstruct or intercept wallet keys. Once that happens, the thieves can sweep funds at any time, without needing direct access to the device again. That’s why funds can be stolen in multiple “waves” even long after a wallet was first set up.

The pattern observed across thousands of addresses suggests a highly automated process. Attackers appear to be scanning for vulnerable wallets, then periodically issuing sweeping transactions that consolidate stolen coins into clusters of known attacker wallets. Those consolidation points, in turn, are how analysts are able to track the total amount stolen and identify when a new wave of thefts begins and ends.

One critical element in Galaxy’s warning is the specific mention of single-signature funds. In a single-signature (single-sig) setup, only one private key is required to move coins. If that key is exposed-even once-an attacker can fully control the funds. By contrast, multi-signature (multi-sig) schemes require multiple independent keys to authorize a transaction, making large-scale automated theft significantly harder. Many security professionals now regard multi-sig, or at least multi-device key management, as essential for holding substantial amounts of Bitcoin.

Hardware wallets like the Coldcard are generally marketed as one of the safest ways to store cryptocurrency because the private keys never leave the device and are not exposed to internet-connected systems. Incidents like this highlight an uncomfortable reality: when something goes wrong at the firmware, supply-chain or key-generation level, even a “cold” device can become a single point of catastrophic failure. The very convenience and security that attract long-term holders can turn into a liability if a flaw is discovered after thousands of users have already adopted the product.

For current Coldcard users, the immediate question is how to assess whether they are at risk. While detailed guidance will depend on the precise nature of the vulnerability, some broad rules are emerging from security analysts. Funds held in older, single-sig wallets created with potentially compromised firmware or unsafe key-generation methods are the main concern. Wallets that have since rotated to new seed phrases generated in a verifiably secure way, or that now use robust multi-sig setups with keys across different devices and vendors, should be significantly safer, provided each step was performed carefully.

If there is any doubt, the conservative approach is to treat the wallet as compromised by default. That means generating a brand-new wallet on a trusted, up-to-date device, writing down a fresh seed phrase offline, testing a small transfer first, and only then migrating the full balance. Crucially, users should avoid simply reusing an old seed on a new device, since that would not remove the attackers’ access if the original seed was already exposed.

The incident also underlines the importance of rigorous operational security around backup phrases. Even the most robust hardware design cannot compensate for seed words that have been photographed, stored in cloud notes, typed into untrusted computers, or revealed to others. Attackers frequently combine a product-level weakness with poor user hygiene to maximize their chances of success.

From a broader industry perspective, the Coldcard theft spree raises questions about transparency, firmware verification and third-party audits in the hardware wallet market. Users increasingly expect manufacturers to provide reproducible builds, open or auditable codebases, independent security reviews, and clear disclosure timelines when vulnerabilities are discovered. The absence of such practices can turn a niche vulnerability into a large-scale financial disaster, as appears to be happening here.

Regulators and enforcement agencies are also paying close attention to cases like this. With roughly 1,367 BTC already identified as stolen, the sums involved cross the threshold where financial crime units, cyber task forces and sanctions authorities start prioritizing collaborative investigations. Galaxy’s decision to share around 600 attacker-linked addresses with official bodies is likely aimed at making it harder for the thieves to cash out via regulated exchanges or custodians, even if fully recovering the funds remains unlikely.

For individual Bitcoin holders, the lesson is blunt but useful: hardware wallets are a crucial layer of defense, not a magic shield. Diversifying security-across devices, key types, physical locations and even vendors-can dramatically reduce the blast radius of any single exploit. Adopting multi-sig for larger holdings, keeping firmware current, verifying downloads, and periodically reviewing one’s setup against current best practices can make the difference between a close call and a total loss.

As the third wave of thefts makes clear, the Coldcard exploit is not a historical curiosity but an active threat. Until all vulnerable wallets are rotated or drained, the attackers have a standing invitation to continue sweeping funds. Holders who suspect any exposure should act before the next wave hits, rather than waiting to find their balance at zero.