Galaxy Research expanded the scope of the Coldcard wallet security incident, identifying 1,196 addresses that lost 1,082.65 Bitcoin during a 41-minute window. The analysis pushes estimated losses to $70 million.
The incident centers on Coldcard hardware wallets, which store private keys offline and function as a primary custody solution for institutional and retail holders. The concentrated theft window signals a coordinated attack exploiting a shared vulnerability rather than random compromises.
Galaxy's findings reveal the attack operated with surgical precision. Attackers accessed multiple wallets simultaneously within a narrow timeframe, suggesting either a zero-day exploit in Coldcard's firmware or a supply-chain compromise affecting a batch of devices. The speed and scale rule out individual user error or phishing campaigns.
Initial reports pegged losses lower, but Galaxy's on-chain analysis uncovered additional affected addresses. The 1,082.65 Bitcoin total represents holdings spread across different Coldcard models and firmware versions, indicating the vulnerability spans multiple product generations.
Coldcard manufacturer Coinkite has not released a formal postmortem detailing the attack vector. The company typically markets hardware wallets as "airgapped" solutions, meaning they never connect to the internet directly. A successful mass compromise despite this design raises questions about physical supply-chain security or a previously unknown firmware flaw.
The incident hits hard at institutional confidence in dedicated hardware storage. Many large holders rely on Coldcard specifically because of its offline-first architecture and open-source firmware. A breach of this magnitude undermines that trust positioning.
Bitcoin holders with older Coldcard units face immediate pressure to migrate funds to alternative storage solutions, creating operational friction. The window for safe transfers narrows if attackers continue accessing compromised wallets.
This event parallels previous hardware wallet incidents where manufacturing vulnerabilities or firmware exploits created mass exposure. It underscores
