A hardware wallet brand long regarded as one of Bitcoin's most trusted cold-storage solutions is now at the center of a deepening financial crisis. Losses tied to Coldcard wallets have climbed to nearly $114 million, as on-chain data reveals a sharp and alarming spike in small Bitcoin transfers — those under one full Bitcoin — rising to activity levels not recorded since the chaotic days immediately following the collapse of FTX in late 2022. For a segment of the Bitcoin community that chose hardware wallets precisely to insulate themselves from exchange-counterparty risk, the developments represent a particularly bitter irony.
The sub-1 BTC transfer surge is not merely a statistical curiosity. When retail-scale Bitcoin movements spike to crisis-era benchmarks, researchers and on-chain analysts typically interpret the pattern as evidence of distressed liquidation, rapid asset redistribution following a theft, or panic-driven fragmentation of holdings. In the Coldcard context, Galaxy Research has framed the pattern in starker terms: the firm flagged the activity as consistent with a likely fourth wave of thefts, suggesting that whatever vulnerability or exploitation vector is being used against Coldcard users has not been contained.
The progression from a first wave through to a probable fourth is significant from a forensic standpoint. Multi-wave theft patterns in cryptocurrency typically indicate either a persistent software or firmware vulnerability that has not been fully patched, a compromise in the supply chain delivering devices to end users, or a social engineering campaign sophisticated enough to extract seed phrases or signing keys iteratively across a broad victim population. Galaxy Research has not, based on available reporting, pinpointed a single definitive attack vector — but the escalating wave structure implies that whatever mechanism is being exploited remains active and accessible to threat actors.
The $114 million figure places the Coldcard incident among the more consequential hardware-wallet security events on record. Hardware wallets occupy a foundational position in Bitcoin's security architecture. The entire value proposition of devices like Coldcard is the air-gap between private keys and internet-connected systems — the premise that a physically secured device eliminates the remote-access attack surface. When losses at this scale accumulate against a hardware wallet brand, the implications extend well beyond the individual victims. Institutional participants evaluating cold-storage custody solutions, Bitcoin treasury operations at listed companies, and sovereign-level Bitcoin reserves all have reason to reassess protocols and vendor assumptions.
The FTX parallel embedded in the data deserves careful unpacking. The days immediately following FTX's implosion in November 2022 produced extraordinary on-chain movement as users scrambled to withdraw assets from every exchange they could access, fragmenting holdings into smaller, self-custodied tranches out of sheer institutional distrust. That the current environment is generating comparable small-transfer volumes — not from exchange panic, but apparently from theft and its aftermath — suggests a different but equally corrosive form of fear: the fear that self-custody itself may no longer be safe. This is an emotionally and practically significant threshold for the Bitcoin ecosystem to cross.
On-chain forensics firms and independent researchers will be tracking the movement of funds connected to each wave of thefts. Bitcoin's transparent ledger means that stolen coins are permanently traceable, even if mixing services or chain-hop maneuvers are used to obfuscate their trail. Law enforcement agencies in jurisdictions with mature crypto-crime units — including the United States Federal Bureau of Investigation's cyber division and Europol's European Cybercrime Centre — have demonstrated in prior high-profile cases that patient, multi-year chain-analysis can eventually identify and prosecute perpetrators. Whether that offers cold comfort to victims who have already seen their holdings drained is another matter.
For Coldcard's manufacturer and the broader hardware wallet industry, the reputational and commercial stakes could not be higher. Competing cold-storage providers — and custodial solutions offered by regulated financial institutions — stand to absorb market share if confidence in self-custody devices erodes. The timing is particularly fraught given the elevated institutional interest in Bitcoin following spot exchange-traded fund approvals in the United States and the asset class's growing presence on corporate balance sheets globally. Sophisticated capital allocators now routinely stress-test custody arrangements, and a $114 million loss event tied to a specific hardware brand will feature prominently in those assessments.
What This Means
The convergence of $114 million in losses, a Galaxy Research warning of a probable fourth theft wave, and small-transfer activity matching post-FTX chaos levels signals that the Coldcard incident has moved well beyond an isolated security anomaly. It is an unfolding, multi-phase event that challenges core assumptions about hardware wallet security. Until the attack vector is definitively identified, publicly disclosed, and patched — and until affected users receive authoritative guidance — the episode will continue to cast a shadow over self-custody as a risk management strategy. The Bitcoin community, hardware wallet vendors, and institutional custodians should treat Galaxy Research's wave-four warning not as background noise, but as an active operational alert.
Written by the editorial team — independent journalism powered by Codego Press.