NewsCryptoGalaxy Research Estimates Coldcard-Linked Bitcoin Thefts Exceed $100 Million Across Three Confirmed Attack Waves

Galaxy Research Estimates Coldcard-Linked Bitcoin Thefts Exceed $100 Million Across Three Confirmed Attack Waves

Author: CoinWy·

Key Takeaways

  • Galaxy's research arm estimates that confirmed bitcoin thefts tied to the Coldcard hardware wallet have exceeded $100 million across three distinct attack waves.
  • The confirmed losses are linked to a seed generation vulnerability in Coldcard's Mk3 devices rather than phishing or user error.
  • The revised $100 million figure represents only verified thefts and does not encompass the full scope of potentially affected users.
  • Following the exploit, some investors reversed the typical post-crisis pattern by sending bitcoin back to exchanges instead of withdrawing to self-custody.
  • Galaxy launched a $5 million bitcoin security fund connected to the Coldcard incident to support broader security efforts.
Galaxy Research Estimates Coldcard-Linked Bitcoin Thefts Exceed $100 Million Across Three Confirmed Attack Waves

Galaxy's research division now estimates that confirmed bitcoin thefts tied to the Coldcard hardware wallet have surpassed $100 million, distributed across three distinct attack waves. The figure represents a significant escalation in what has become one of the year's most closely monitored self-custody security incidents, and it underscores an uncomfortable reality for the bitcoin community: even devices specifically engineered for offline key storage can harbor exploitable weaknesses.

Galaxy's Revised Estimates

According to reporting on the firm's findings, Galaxy's research arm categorizes the confirmed losses into three separate attack waves rather than a single continuous exploit. The $100 million total marks a sharp increase from Galaxy's earlier analysis, which had raised the Coldcard loss estimate to $70 million as additional affected wallets were identified and traced.

Galaxy draws a clear distinction between confirmed thefts and a broader pool of suspected losses that remain unquantified. The revised figure reflects only verified cases, not the full scope of potentially affected users.

The significance for bitcoin holders is substantial. Coldcard, manufactured by Coinkite, is a widely adopted cold-storage device specifically marketed for self-custody security. Its appeal has long rested on its air-gapped design — the device is built to operate without a direct internet connection, a feature intended to minimize exposure to remote attacks. A confirmed nine-figure loss concentrated on a single hardware product line raises pressing questions about how the compromises occurred and whether additional users remain at risk. Hardware wallets from manufacturers including Coldcard, Ledger, and Trezor have been widely promoted as the gold standard for self-custody in the years since major exchange failures such as Mt. Gox and FTX eroded trust in centralized platforms, making this incident particularly consequential for the broader self-custody narrative.

Three Attack Waves and the Seed Generation Vulnerability

Galaxy's analysis groups the confirmed thefts into three waves, though the brief does not specify precise dates, chronological ordering, or the distinct attacker methods behind each individual wave.

A common thread connecting the incidents involves seed generation. Coinkite has published a warning related to Mk3 seed generation — the process by which a wallet's recovery phrase is created. A wallet's seed phrase functions as its master key: anyone who can reconstruct or predict it gains full control over the associated funds. A weakness in seed generation can potentially allow an attacker to reconstruct the cryptographic keys protecting a user's funds without needing physical access to the device or any phishing interaction with the user.

What remains unspecified is how each of the three waves maps to specific methods, timing, or attacker groups. These mechanics are not detailed in the available evidence and should not be inferred beyond what Galaxy and Coinkite have officially stated.

Market Reaction and Industry Response

The incident has already produced observable effects on market behavior. CoinDesk reported that, unlike the FTX collapse — which prompted investors to withdraw bitcoin from exchanges — the Coldcard exploit led some investors to send bitcoin back to exchanges, reversing the typical self-custody narrative. The reversal is notable because it reflects a shift in how some users are weighing the relative risks of self-custody versus exchange custody. CoinDesk framed its reporting around an $88 million figure for the exploit.

Galaxy has also taken concrete action beyond its research analysis, launching a $5 million bitcoin security fund connected to the episode.

Implications for Device Security vs. User Error

A critical distinction in this incident is the apparent link between the confirmed losses and how keys were generated on the device itself, rather than individual phishing attacks or careless key handling by users. This points responsibility toward the hardware and firmware process rather than user error alone — a distinction that carries significant weight for how the hardware wallet industry and its customers assess and respond to risk.

For current or prospective Coldcard users, the practical guidance centers on the seed generation warning. Users relying on potentially affected devices should follow Coinkite's official recommendations on verifying or regenerating their wallets.

The scale of the confirmed losses — a nine-figure total concentrated on one hardware wallet line and spread across three separate waves — places this incident among the most consequential self-custody security events documented this year, and it adds to ongoing scrutiny of seed generation practices across the broader hardware wallet ecosystem.

This article is for informational purposes only and does not constitute financial or investment advice.