A firmware vulnerability embedded in Coldcard hardware wallets — manufactured by Coinkite — has now produced what researchers believe to be three distinct waves of unauthorized Bitcoin transfers, with the cumulative damage reaching 1,367.05 BTC across 4,585 compromised addresses. Galaxy Research published an update confirming the discovery of a third suspected attack wave, valuing the combined transfers at approximately $88.6 million at the time of publication. The escalating toll signals that the threat actor — or actors — behind the campaign remain active, methodical, and capable of adapting their approach with each successive wave.

A Campaign That Keeps Growing

What began as a disturbing but contained incident has expanded into one of the more significant hardware wallet security failures the Bitcoin ecosystem has witnessed in recent years. The third wave alone accounted for 207.7294 BTC, a figure that underscores the continuing exposure of users who generated wallet addresses using the affected Coldcard firmware and have not yet moved their funds to secure addresses. Each wave has added to an already alarming ledger, and the cumulative total of 1,367.05 BTC now sits as a stark measure of how deeply the vulnerability has been exploited.

The breadth of the attack — spanning 4,585 distinct addresses — suggests the underlying firmware flaw produced predictable or recoverable private keys across a wide population of devices or seed generation events. Hardware wallets are premised on the guarantee that private key material never leaves the device and cannot be derived externally. When that guarantee fails at the firmware level, the consequences are not limited to a single user or a single transaction; they cascade across every address generated during the vulnerable period, creating an attack surface that a motivated adversary can mine repeatedly over time.

Third Wave Signals Tactical Adaptation

Critically, Galaxy Research noted that the third wave employed a different methodology from its predecessors, a detail that carries significant implications for both attribution and mitigation. A threat actor who varies technique between waves is demonstrating operational sophistication — either to evade on-chain heuristics that researchers and exchanges use to flag suspicious flows, or to access a different subset of vulnerable addresses that prior methods had not yet reached. Either interpretation points to an adversary who has studied the vulnerability carefully and is deploying it in a structured, deliberate manner rather than opportunistically draining funds in a single sweep.

This adaptive behavior also complicates the forensic picture. Blockchain analytics firms typically build detection models around consistent behavioral fingerprints: similar transaction structures, timing patterns, consolidation addresses. When an attacker shifts methodology mid-campaign, existing models must be retrained or supplemented, and previously categorized transactions may need to be re-examined to determine whether they belong to the same actor or represent a copycat who identified the same firmware weakness independently.

Implications for the Hardware Wallet Industry

The Coldcard incident arrives at a moment when hardware wallets are being marketed more aggressively than ever as the definitive answer to exchange hacks and custodial risk. The core value proposition of devices like Coldcard is that self-custody, implemented correctly, removes counterparty risk. A firmware-level vulnerability inverts that argument: it transforms the security device itself into the attack vector, and it does so silently, without any signal visible to the user on the device screen or in their transaction history — until funds begin moving without authorization.

For retail and institutional holders alike, the incident reinforces a principle that security professionals have long advocated: hardware wallet firmware must be treated with the same scrutiny applied to exchange custody arrangements. That means verifying firmware integrity at installation, monitoring for vendor security advisories promptly, and — most critically — rotating funds to freshly generated addresses whenever a credible vulnerability is disclosed. Users who generated addresses using affected Coldcard firmware and have not yet acted remain exposed as long as those addresses hold a balance.

What This Means for Affected Users and the Broader Market

With $88.6 million in Bitcoin already transferred out of victim addresses and a third attack wave demonstrating that the campaign has not run its course, the immediate priority for anyone holding funds on a Coldcard device generated during the vulnerable firmware period is to treat those addresses as compromised. Galaxy Research's ongoing monitoring — which has now identified three distinct waves across 4,585 addresses — provides the clearest public accounting available, but the researchers' ability to detect future waves depends on the attacker continuing to use on-chain patterns that remain distinguishable.

The broader market implication is a renewed stress test for trust in hardware wallet manufacturers. Coinkite built Coldcard's reputation on open-source firmware and a security-first philosophy. How the company responds — in terms of transparency about the root cause, the precise scope of vulnerable firmware versions, and concrete guidance for affected users — will determine whether that reputation can be meaningfully rebuilt. The cryptocurrency industry has weathered exchange collapses, protocol exploits, and bridge hacks, but a sustained firmware-level attack on one of its most trusted self-custody devices represents a qualitatively different kind of systemic vulnerability, one that strikes at the foundational premise of sovereign Bitcoin storage.

Written by the editorial team — independent journalism powered by Codego Press.