A meticulously orchestrated campaign targeting Coldcard hardware wallets has escalated into one of the most significant Bitcoin theft events in recent memory, with a third wave of confirmed drains pushing total observed losses to approximately 1,367 Bitcoin — equivalent to roughly $88 million — spread across 4,585 compromised addresses, according to findings published by Galaxy Research. The fact that attackers continue to drain wallets even as the incident is under public scrutiny raises urgent questions about the nature and depth of the underlying exploit.
Coldcard hardware wallets have long been regarded as among the most secure consumer-grade Bitcoin storage solutions available. Manufactured by Coinkite, the devices are popular precisely because they are built for adversarial environments — air-gapped, open-source firmware, with a strong emphasis on cryptographic integrity. For an exploit to breach wallets at this scale — 4,585 distinct addresses — and to sustain activity across at least three separate waves suggests the vulnerability is either structural in nature or that a significant number of users are sharing a common attack surface, such as a compromised seed generation process, a supply-chain weakness, or a coordination failure in key management practices.
The progression of the attack is particularly alarming. Multi-wave theft campaigns are not random opportunism; they are methodical. The first wave typically targets the most accessible or highest-value wallets. Subsequent waves — and in this case a confirmed third wave — indicate that attackers possess either a persistent list of vulnerable addresses compiled in advance, or the ability to continue identifying new targets in real time. Either scenario implies a level of preparation and intelligence that goes well beyond a simple phishing campaign or isolated firmware compromise.
At 1,367 BTC across 4,585 addresses, the average loss per address works out to approximately 0.3 BTC per wallet — a figure that suggests this is not a campaign targeting exclusively high-net-worth holders or institutional custodians. The distribution implies a broad sweep of retail-level Coldcard users, the very demographic that adopted the device as a self-custody alternative to exchange storage. The cruel irony is that these users took the security-conscious step of moving assets off exchanges and into hardware wallets, only to find themselves exposed through what appears to be a systemic weakness in the very tool they trusted for protection.
The $88 million figure, while significant, almost certainly understates the total exposure. Galaxy Research's methodology, by its own framing, reflects observed losses — wallets that have already been drained and identified. Addresses that have been compromised but not yet emptied, or incidents that have not yet been detected and cross-referenced on-chain, would not be captured in the current tally. As blockchain analytics firms and independent researchers continue combing transaction histories, it is reasonable to expect the confirmed figure to rise further.
Hardware wallet security has become a critical pressure point in the broader self-custody conversation. The appeal of devices like Coldcard rests on a fundamental promise: that private keys never touch an internet-connected environment, making remote compromise theoretically impossible. When that promise breaks down — whether through supply-chain infiltration, firmware vulnerabilities, or flaws in the entropy used to generate seed phrases — the consequences are irreversible. Unlike a hacked exchange, where there exists at least the theoretical possibility of recovery through legal recourse or reserve funds, self-custody theft leaves victims with no counterparty to petition and no insurance backstop.
Regulators and industry bodies have for years debated the appropriate oversight framework for self-custody solutions. The European Banking Authority and the Bank for International Settlements have both flagged consumer protection gaps in the hardware wallet market, where manufacturers are subject to few mandatory security audit requirements compared to regulated financial institutions. This incident may intensify calls for mandatory third-party security certifications and supply-chain transparency standards for hardware wallet producers operating in major markets.
What This Means for Bitcoin Self-Custody
The Coldcard exploit is not merely a product-specific crisis — it is a stress test for the entire self-custody model. As the Bitcoin ecosystem matures and hardware wallets become the de facto standard for serious holders, the security expectations attached to these devices must rise in proportion. Galaxy Research's documentation of three confirmed theft waves totaling 1,367 BTC across 4,585 addresses at an $88 million loss threshold will likely serve as a watershed reference point in that conversation. Affected users should immediately assess whether their wallets fall within the compromised address set, consider transferring remaining holdings to freshly generated wallets using unaffected hardware, and monitor official communications from Coinkite regarding the scope and root cause of the vulnerability. Until a definitive explanation is published, caution demands treating all existing Coldcard deployments as potentially at risk.
Written by the editorial team — independent journalism powered by Codego Press.