Losses tied to the Coldcard wallet theft may climb past $150 million, according to Decrypt’s report citing Galaxy Research. Galaxy has confirmed the theft of 1,778 BTC, worth about $112 million, and said the total could rise to 2,417 BTC, or roughly $151.3 million, if an unconfirmed fourth wave is included. The firm said more than 5,200 addresses were drained and that it has contacted over 190 victims.
The attack began early on July 30, with the last confirmed attacker activity recorded on Aug. 6. Galaxy said the pace of thefts has slowed, possibly because many exposed users have already moved funds or because most of the vulnerable balances were already emptied.
The root cause was traced to a 2021 firmware change. That update switched seed generation from a hardware random number generator to a software-based method, cutting entropy from 128 bits to as low as 40 bits. Galaxy said an attacker could reconstruct the seed using only a device serial number and clock state, without physical access or phishing. It urged users running single-signature Coldcard setups to move funds to fresh addresses immediately.
A theft campaign targeting the Bitcoin hardware wallet Coldcard may become one of the costliest incidents in the history of hardware wallets. Decrypt, citing Galaxy Research, reported that the draining activity has slowed, but total losses may still top $150 million.
Confirmed losses stand at 1,778 BTC, with total exposure seen at 2,417 BTC
Galaxy said it has confirmed the theft of 1,778 BTC, worth about $112 million. If an unconfirmed fourth wave is counted, the total could reach 2,417 BTC, or about $151.3 million.
More than 5,200 addresses were drained, and over 190 victims have been contacted. The attack started early on July 30, and the last confirmed attacker activity was recorded on Aug. 6.
Galaxy said the slowdown may reflect two possibilities: many vulnerable users may already have moved their funds, or most of the accessible balances may already have been taken.
The issue was traced to a 2021 firmware change
According to the report, the problem came from a 2021 firmware update. That change shifted seed generation from a hardware random number generator to software, reducing entropy from 128 bits to as low as 40 bits.
With that weakness in place, an attacker could reconstruct a seed using only the device serial number and clock state. Physical access was not required, and neither was phishing.
ABMedia also noted that ChainNews had previously broken down the root cause of the 2021 build error.
Galaxy urged single-signature users to move funds
Galaxy advised users with single-signature Coldcard setups to move funds to new addresses immediately.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.