Coldcard Exploit Hit Canadian Holders Hardest, Chainalysis Says
Key Takeaways
- •Chainalysis attributed 25% of the Coldcard exploit’s losses to Canadian users, making Canada the most affected region.
- •The United States and Thailand were also heavily affected by the ongoing exploit.
- •Other estimates put total losses from the Coldcard hack at more than $110 million to $150 million.
- •The Red Team initiative has scanned 150 code repositories and says it is finding about one serious or critical vulnerability per hour in AI-assisted audits.
- •Onchain Lens said the attack stole more than 1,816 BTC from 5,200 affected addresses, with most of the funds still sitting in destination wallets.

The Coldcard wallet exploit has affected Canadian holders the most, with 25% of the attributed losses traced to Canadian users, according to Chainalysis. The firm said the disproportionate impact was tied to Coldcard’s local popularity, which was amplified by influencer campaigns.
Chainalysis used on-chain data and available connections to exchanges to link the Coldcard address database to the most likely regions. Canada has long been associated with early Bitcoin adoption and with influencers promoting Bitcoin maximalism, which Chainalysis said helped drive wider use of the wallet despite inadequate entropy and vulnerable address generation.
The United States and Thailand have also been heavily affected by the ongoing exploits, based on Chainalysis data. The regional split matters because it shows how a wallet flaw can ripple through different user bases once exposed, especially when self-custody tools are widely adopted before problems are identified.
As Cryptopolitan reported earlier, the attack on Coldcard has affected broader BTC sentiment and the trend toward self-custody. Other estimates put losses from the Coldcard hack at more than $110 million to $150 million.
Red Team seeks to limit Coldcard and similar attacks
The Coldcard attacks prompted one of the largest efforts to identify vulnerabilities in the Bitcoin ecosystem.
In the early days after the exploit, some funds were moved in white-hat hacking attempts. The Red Team initiative is expanding that approach, using AI analysis to find similar vulnerabilities.
The Red Team has spent more than $20,000 on tokens and has secured additional funding to continue its work. Rob Hamilton, CEO of AnchorWatch, is spearheading the initiative. So far, the team has scanned 150 code repositories and has tried to contact all related parties.
The Red Team has also contacted OpenAI to run Cyber Harness, a more thorough scanning model for vulnerabilities in the most critical parts of the Bitcoin ecosystem.
Additional reports have cited the use of the free Kimi K3 model to find flaws in crypto codebases. The initiative also highlights new opportunities for AI-assisted attacks, in which threat actors identify vulnerabilities first.
The recent attacks came as some of the most widely used AI models lowered their pricing, contributing to the steepest weekly decline of the year. Free models also made AI-assisted attacks easier.
Red Team has said it is finding roughly one serious or critical vulnerability for every hour of its AI-assisted audits. The team deploys its testing harnesses across crypto libraries, wallets, and infrastructure, and has contacted several Bitcoin-related projects in the past 12 hours.
Coldcard attack may involve 15 different entities
The Coldcard attack is not limited to a single threat actor, but to multiple entities. Once the vulnerability became known, many threat actors were able to drain exposed wallets.
According to Alex Thorn, head of Firmwide Research, the attack unfolded in multiple waves, with the first attack being the largest.
Onchain Lens said the ongoing attack stole more than 1,816 BTC from 5,200 affected addresses. The stolen funds were initially considered frozen. Unlike other crypto attacks, where mixing typically happens within hours of the exploit, most of the BTC remains in destination addresses.
On-chain reports show that one wallet holding about 64 stolen BTC may have engaged in early mixing. The wallet carried out a series of transactions in which 10 BTC were mixed and 54 BTC were moved to a new address.
For now, most destination wallets have been tagged by law enforcement, although mixing can make some of the funds unreachable.
Coldcard owners are being urged not only to update firmware, but also to generate a new secure wallet seed and move funds while setting a higher transaction fee. Some funds have been recovered by paying more and front-running the attacker’s transaction.