Galaxy Research has identified 1,596 BTC stolen from 7,300 addresses across three confirmed waves of attacks targeting Coldcard hardware wallet users, with cumulative losses already representing a significant blow to Bitcoin self-custody security. The firm has identified but not yet confirmed a fourth wave of attacks that, if verified, would push the total stolen to approximately 2,000 BTC, or around $130 million at current prices.
Why it matters
Coldcard is widely regarded as one of the most security-hardened Bitcoin hardware wallets on the market, favored by technically sophisticated users and institutions precisely because of its air-gapped design and open-source firmware. A breach of this scale, if the fourth wave is confirmed, would represent one of the largest hardware wallet exploits in Bitcoin's history and would force a broad reassessment of assumptions around cold storage security across the self-custody ecosystem.
Market impact
The confirmation of additional attack waves could trigger a wave of precautionary fund movements as Coldcard users audit their holdings and migrate to alternative storage solutions. For the broader Bitcoin market, a $130 million loss event concentrated in self-custody wallets is a reputational hit to the "not your keys, not your coins" thesis that underpins retail and institutional cold storage adoption. Traders should watch for on-chain activity from the 7,300 identified addresses and any official response from Coinkite, Coldcard's manufacturer.
Frequently asked questions
-
How much Bitcoin has been confirmed stolen in the Coldcard hack so far?
Galaxy Research has confirmed 1,596 BTC stolen from 7,300 addresses across three separate attack waves. A fourth wave has been identified but not yet confirmed.
-
What would total losses reach if the fourth attack wave is confirmed?
A confirmed fourth wave would bring total stolen funds to approximately 2,000 BTC, worth around $130 million at current prices.
-
Why is a Coldcard hack particularly significant for Bitcoin security?
Coldcard is considered one of the most security-hardened hardware wallets available, used by technically sophisticated holders and institutions. A large-scale exploit undermines confidence in air-gapped cold storage as a security standard.
-
How many addresses were affected across the confirmed attack waves?
Galaxy Research identified 7,300 addresses compromised across the three confirmed waves of the Coldcard hack.
-
What should Coldcard users do in response to this hack?
Users should audit their holdings, monitor the 7,300 flagged addresses for on-chain activity, and watch for an official statement from Coinkite, Coldcard's manufacturer, regarding the scope and cause of the breach.
TheBlock