NewsCryptoGalaxy says at least 15 attackers exploited Coldcard vulnerability

Galaxy says at least 15 attackers exploited Coldcard vulnerability

Author: Cointelegraph·

Key Takeaways

  • Galaxy Digital now believes at least 15 different attackers exploited the Coldcard vulnerability.
  • New victim reports helped investigators identify attacks that would have been harder to trace than a centralized exchange breach.
  • Galaxy Research estimates confirmed losses at $100 million across three attack waves and sees a possible fourth wave that could lift losses to about $130 million in bitcoin.
  • The exploit has renewed debate over cold storage wallet security and whether users are safer holding their own bitcoin.
  • Commentators disagreed on the role of AI, with some saying models quickly rediscovered the flaw while others said the vulnerability was already public when tested.
Galaxy says at least 15 attackers exploited Coldcard vulnerability

At least 15 different attackers have exploited the Coldcard vulnerability, according to Galaxy Digital head of research Alex Thorn, who cited new victim reports received after the incident.

Thorn said on Tuesday that the additional reports allowed Galaxy to identify attackers that would otherwise have gone undiscovered, since the exploit’s nature differed from a hack on a centralized exchange, where losses and activity are often easier to trace from a single point of failure.

“Due to one single victim’s report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses,” Thorn wrote in a Tuesday X post.

Galaxy Research now estimates that losses from the Coldcard exploit have reached $100 million across three confirmed attack waves. The company also identified a suspected fourth wave that could lift total losses to about $130 million in Bitcoin (BTC).

The attack has renewed debate over the security of cold storage wallets and whether users are safer when they hold their own Bitcoin. It also underscores how incident reporting can change the scope of an exploit after the fact, especially when affected funds are spread across many addresses rather than concentrated on one platform.

Dragonfly managing partner Haseeb Qureshi wrote that roughly “$2 of AI hardening” could have prevented the Coldcard exploit, citing social media reports that some AI models rediscovered the vulnerability in less than 20 minutes.

Qureshi made the comments in response to multiple social media users claiming that Claude regenerated the vulnerability in just eight minutes. He said those results may have been affected by web search and added that the open-source AI model GLM 5.2 rediscovered the attack in 20 minutes with web access turned off.

However, it is unlikely that AI models would have independently discovered the vulnerability before it was made public, Tatsapat Saerejittima, data lead at crypto analytics platform Tokenomist, told Cointelegraph. He said:

“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.”

Francesco, co-founder of crypto research company Castle Labs, said the improving capabilities of AI models are sharply reducing the cost and time required to find new cryptocurrency vulnerabilities. He added that Coldcard’s private key setup may have contributed to the issue.

Coldcard used a “level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug, making the job easier,” he told Cointelegraph.

Francesco, who asked that Cointelegraph not use his last name, said he expects the cost of bug discovery to keep falling as AI models become more capable and more widely used in both cybersecurity and exploits.

Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says

Magazine: Does Botanix’s failure prove Bitcoiners don’t care about DeFi?