Galaxy Research отслеживает кражу Bitcoin с Coldcard на $100 млн
Ключевые выводы
- •Galaxy Research подтвердила, что взлом кошелька Coldcard привёл к потерям свыше $100 million и затронул 1,596 stolen Bitcoin примерно на 7,300 адресах.
- •Подтверждены три волны атак; предполагаемая четвёртая волна может увеличить совокупный ущерб примерно до 2,055 BTC стоимостью около $130 million.
- •Инженеры в Block первоначально обнаружили первую волну атаки, а отчёты жертв помогли выявить последующие волны и дополнительные скомпрометированные адреса.
- •Примерно 90% похищенных Bitcoin не перемещались on-chain, что соответствует ранее наблюдавшимся схемам крупных краж криптовалюты.
- •Galaxy Research передала подтверждённые адреса атакующих и жертв правоохранительным органам США, криптовалютным биржам и компаниям по комплаенсу для содействия расследованию.

Galaxy Research has confirmed that losses from the Coldcard Bitcoin wallet hack have surpassed $100 million, with researchers identifying 1,596 stolen Bitcoin spread across approximately 7,300 addresses. Coldcard, a hardware wallet produced by Coinkite, is widely used by Bitcoin holders for cold storage of private keys offline, a setup generally regarded as one of the more secure self-custody configurations — making the scale of the compromise particularly notable for the hardware wallet ecosystem.
The research team detailed its findings in a comprehensive thread on X (source), identifying three confirmed attack waves responsible for the thefts. A suspected fourth wave, if verified, would raise total estimated losses to approximately 2,055 BTC, valued near $130 million.
Three Confirmed Attack Waves
According to Galaxy Research, engineers at Block first detected Wave 1. The team subsequently corroborated the incident through reports submitted by affected users. Victim reports also played a critical role in uncovering Waves 2 and 3.
New confirmations continue to arrive as additional users review their wallet activity. Most victims appeared in only a single attack wave, though researchers noted that some addresses were compromised in two separate waves.
Beyond the three major attacks, the report identified 14 smaller incidents. Galaxy Research suggested these cases may involve different attackers exploiting the same known vulnerability. The coordinated, multi-wave pattern of exploitation underscores a broader challenge in hardware wallet security: once a vulnerability is discovered, multiple threat actors can independently leverage it before users migrate to patched firmware or fresh seed phrases.
Ongoing Tracing Efforts and Possible Fourth Wave
Galaxy Research reported that 73 victims have contacted Alex Thorn for assistance with tracing stolen funds. These reports have helped investigators identify additional attacker and victim addresses.
The team also identified a possible fourth wave but excluded it from confirmed totals because victims have not yet verified their inclusion. Researchers stated they hold medium-high confidence that the activity in question belongs to an attacker.
Most Stolen Bitcoin Remains Unmoved
According to Galaxy Research, approximately 90% of the stolen Bitcoin has not moved on-chain. Every coin stolen during Waves 1, 2, and 3 remains untouched. The lack of movement is consistent with patterns seen in prior large-scale cryptocurrency thefts, where attackers frequently hold funds dormant — sometimes for extended periods — before attempting to launder or cash out.
The firm has shared confirmed attacker and victim addresses with U.S. federal law enforcement agencies, cryptocurrency exchanges, compliance firms, cyber investigation groups, and other relevant organizations.
Researchers advised Coldcard users who remain uncertain about their wallet security to transfer funds to a fresh seed, or to a custodian or exchange. They also encouraged victims to contact Alex Thorn with drained wallet addresses and attacker transaction IDs to support ongoing tracing efforts.