Coldcard Bitcoin Exploit Losses Reach $111 Million, Galaxy Research Reports
Key Takeaways
- •Galaxy Research has verified the theft of 1,719 Bitcoin, worth approximately $111 million, from Coldcard hardware wallets.
- •Total losses are projected to potentially exceed $130 million and surpass 2,300 BTC as investigators review additional suspect coins.
- •The exploit specifically impacted Coldcard Mk3, Mk4, Mk5, and Q models, with no current evidence implicating other hardware wallets.
- •More than 250 victims, primarily everyday Bitcoin holders, were affected by over 25 distinct attack patterns across three separate waves.
- •The stolen Bitcoin was predominantly held in cold storage for over a year, with none of the compromised funds originating before the March 2021 firmware release.

Galaxy Research has confirmed that 1,719 BTC, valued at approximately $111 million, were stolen in the Coldcard hardware wallet exploit. Coldcard is manufactured by Coinkite and is among the most widely used Bitcoin-only hardware wallets, designed to keep private keys in isolated cold storage away from internet-connected devices. The firm estimates that total losses likely exceed $130 million as researchers continue vetting additional suspect coins.
Alex Thorn, Galaxy's Head of Firmwide Research, has received loss reports from more than 250 victims. Outstanding candidates under review could push confirmed losses beyond 2,300 BTC.
Confirmed Losses and Statistical Profile
Galaxy stated that it only classifies coins as confirmed after establishing high confidence, typically through multiple victim reports. The current confirmed total stands at 1,719 BTC.
According to Thorn's data, individual losses range from 624 satoshis to 58.97 BTC. Measured by address, the median loss is 0.014 BTC and the mean is 0.212 BTC. Measured by reported victim, the median loss reaches 1.022 BTC, with a mean of 4.04 BTC.
Older Bitcoin Dominates Stolen Funds
The stolen coins exhibit a distinct age pattern. Median dormancy stands at 3.5 years, and 88% of stolen coins were at least one year old. Galaxy reported that no stolen coin originated on-chain before March 17, 2021 — a date that coincides with the release of the affected Coldcard firmware. The concentration of theft among long-held coins means that users who maintained what they believed to be secure cold-storage setups over multiple years were nonetheless affected, a pattern that underscores the severity of a firmware-level compromise in a device category whose primary value proposition is key isolation.
The affected hardware models are Coldcard Mk3, Mk4, Mk5, and Q. Researchers said there is currently no evidence implicating other signing devices or wallets.
Multiple Threat Actors and Attack Waves
The investigation has identified more than 25 distinct attack patterns across Waves 1, 2, and 3, indicating the involvement of multiple threat actors.
Galaxy described the victim profile across all three waves as predominantly everyday bitcoin holders rather than large-scale investors, stating that victims are "mostly not whales." The loss distribution — ranging from fractions of a bitcoin to nearly 59 BTC per address — reflects that the exploit affected holders across a wide spectrum of wallet sizes rather than targeting a specific tier.
The research team continues reviewing victim submissions and vetting additional candidate coins before adding them to the confirmed set. Galaxy noted that outstanding candidates could raise confirmed losses above 2,300 BTC as the investigation progresses.