Losses tied to a vulnerability affecting Coldcard hardware wallets have climbed to roughly $70 million, according to Galaxy Research. The firm said nearly 1,200 addresses have been drained of more than 1,000 BTC across transactions it linked to the exploit.
Why it matters
The dollar figure alone is bad enough, but the address count is what reads as the real escalation. A handful of drained wallets points to targeted phishing; nearly 1,200 drained wallets points to a coordinated campaign, likely with a shared vector such as a compromised firmware signer, a counterfeit device, or a flaw in the secure-element workflow that the broader Coldcard user base shares. Self-custody is supposed to be the safest seat in the room, and a single vulnerability turning 1,200 cold-storage setups into a $70M collective loss is the kind of stat that pushes users back toward custodial or insured alternatives.
Market impact
Bitcoin self-custody hardware wallets sit at the foundation of the "not your keys, not your coins" pitch, and a supply-chain scare of this size will get attention from every regulator already circling the sector. Watch for any statement from Coinkite (Coldcard's maker), any on-chain tracing labels being applied to the drained addresses, and whether other hardware-wallet vendors begin publishing proactive attestations in response.
Frequently asked questions
-
How much Bitcoin has been lost in the Coldcard vulnerability so far?
Galaxy Research puts losses at roughly $70 million, with more than 1,000 BTC drained across nearly 1,200 addresses it linked to the exploit.
-
How many wallets have been affected by the Coldcard exploit?
Galaxy Research traced nearly 1,200 drained addresses to the exploit, a count that points to a coordinated campaign rather than isolated phishing.
-
What vulnerability is affecting Coldcard hardware wallets?
Galaxy has not publicly named the exact vector. The pattern across 1,200 drained addresses suggests a shared weakness such as a compromised firmware signer, counterfeit devices, or a flaw in the secure-element workflow.
-
Is Coldcard still safe to use for Bitcoin self-custody?
Coinkite, the maker of Coldcard, has not been quoted in the seed. Users should wait for an official statement and any firmware update before moving funds, and consider a fresh device generated offline if exposure is suspected.
-
How does the Coldcard hack affect Bitcoin self-custody more broadly?
A single vulnerability turning 1,200 cold-storage setups into a $70M loss puts supply-chain risk back on the agenda for self-custody users and is likely to push some back toward custodial or insured alternatives.
TheBlock