Security & Audits
Share
A firmware flaw in a March 2021 Coldcard update has enabled attackers to drain approximately 1,367 BTC (~$88.6M) from 4,585 addresses, with Galaxy Research warning the attack remains active and urging immediate fund migration.
A large-scale security exploit targeting Coldcard hardware wallets has resulted in the theft of nearly 1,367 Bitcoin, worth approximately $88.6 million, according to researchers at Galaxy Research, who say the attack remains active and could impact additional users.
The latest findings indicate that attackers have already drained funds from 4,585 Bitcoin addresses, with a third wave of thefts pushing total observed losses close to the $90 million mark.
Researchers are urging anyone using potentially affected Coldcard-generated wallets to transfer their assets immediately.
Galaxy Research reported that an additional 207.73 BTC was stolen during the latest wave of attacks, bringing total estimated losses to approximately 1,367 BTC.
According to Alex Thorn, Galaxy Digital's Head of Firmwide Research, investigators continue to identify both victim and attacker addresses as the exploit unfolds.
"The attack is ongoing," Thorn said in a post on X, advising users to move funds from vulnerable Coldcard-generated addresses without delay.
Galaxy said it has shared hundreds of suspected attacker wallet addresses with law enforcement agencies, compliance providers, and cybersecurity investigators to support ongoing efforts to trace the stolen assets.
The exploit has been linked to a flaw introduced in a March 2021 Coldcard firmware update, which reportedly weakened the randomness used during seed phrase generation.
According to researchers, the issue affected the creation of private keys for certain single-signature wallets, making them significantly easier for attackers to predict than intended.
Galaxy believes the thefts were highly automated and coordinated, with Thorn suggesting the attackers may have used advanced automation tools to systematically identify and empty vulnerable wallets.
He also warned that every affected single-signature wallet generated using the flawed firmware could eventually be compromised if funds remain in those addresses.
Researchers noted that many of the stolen Bitcoin had remained untouched for years before being drained.
Galaxy estimates the compromised funds had been dormant for an average of 3.18 years, indicating that many victims were long-term Bitcoin holders who believed their assets were securely stored offline.
At the time of publication, investigators said the stolen funds remained in attacker-controlled wallets and had not yet been moved further.
The exploit has prompted an unusual response across the Bitcoin community, with some affected users temporarily abandoning self-custody in favor of centralized exchanges or newly generated wallets.
On-chain data shared by CryptoQuant Head of Research Julio Moreno showed that Bitcoin transfers below 1 BTC surged on Friday, with approximately 39,600 BTC moved in a single day.
The figure represents the highest daily volume for transactions under one Bitcoin since November 2022, shortly after the collapse of cryptocurrency exchange FTX, suggesting a wave of smaller holders relocating their assets following news of the exploit.
The migration marks a rare reversal of Bitcoin's long-standing "not your keys, not your coins" philosophy, as security concerns temporarily outweighed the preference for self-custody.
Among those affected was Canadian entrepreneur and coach Jonathan Goodman, who said 18.25 BTC was stolen from his wallets within minutes despite storing his recovery phrase offline in a safety deposit box.
Goodman wrote that he had followed recommended security practices and is now reporting the incident to both law enforcement authorities and Canadian regulators.
The incident has renewed debate over hardware wallet security and the importance of verifying firmware integrity, while highlighting that even offline storage solutions remain vulnerable if cryptographic key generation is compromised.
With the ongoing investigation, security researchers are advising all users who may have created Coldcard single-signature wallets using the affected firmware to immediately transfer their Bitcoin to newly generated wallets created with verified software.
Disclaimer of Warranty
The information provided in this article is for general informational purposes only. We make no warranties about the completeness, reliability, and accuracy of this information. Read full disclaimer
Editor's Picks
In the Same Space

1inch Takes Aim at DeFi’s Idle Liquidity Problem With New Shared Layer
News Desk
Jul 29, 2026
4 min

Top 10 Blockchains by Developer Activity: Ethereum and BNB Chain Lead
News Desk
Jul 27, 2026
3 min

BlackRock, Strategy, and Coinbase Commit $15 Million to Launch Bitcoin Security Consortium
News Desk
Jul 24, 2026
3 min

Is Blockchain Becoming the Financial Infrastructure for Machine Economies?
News Desk
Jul 23, 2026
3 min



