15 Malicious Actors Exploited Coldcard Hardware Wallet Vulnerability

cryptonews.ruPublished on 2026-08-05Last updated on 2026-08-05

Abstract

More than 15 distinct malicious actors exploited a vulnerability in the Coldcard hardware wallet, according to Alex Thorn of Galaxy Digital. Analysis of victim reports, including one involving the theft of under 1 BTC, led to the discovery of an attack that drained 12 BTC from 126 addresses. The estimated losses from this exploit have reached $100 million across three confirmed attack waves, with a potential fourth wave possibly raising total losses to around $130 million in Bitcoin. The incident has reignited debate about the security of cold storage. Notably, Haseeb Qureshi of Dragonfly suggested that spending roughly $2 on AI-powered code auditing could have potentially prevented the exploit, as some AI models reportedly identified the vulnerability in under 20 minutes post-disclosure. The core flaw was a critical reduction in private key entropy within the device's firmware. Instead of the standard 128 bits of entropy provided by a 12-word seed phrase, Coldcard's key generation was limited to just 40 bits, significantly simplifying the task for attackers. This case draws parallels to the 2023 "Milk Sad" vulnerability in Libbitcoin Explorer, highlighting how firmware errors compromising entropy can repeat across different products. The widespread exploitation by over 15 parties underscores how quickly vulnerability information spreads after disclosure.

More than 15 separate malicious actors exploited the Coldcard vulnerability — this assessment was given by Alex Thorn, Head of Research at Galaxy Digital, based on new reports from victims. Thorn posted on social media X that victims' complaints helped the company identify attackers who would otherwise have remained undetected: the nature of this exploit differs from hacking a centralized exchange.

"Thanks to a single victim's report of a theft of less than 1 $BTC, we discovered a new attack that resulted in 12 $BTC being drained from 126 addresses," wrote Thorn.

The estimated losses from the Coldcard exploit have risen to $100 million across three confirmed attack waves, according to Galaxy Research. A fourth wave has also been identified, potentially bringing total losses to around $130 million in bitcoin.

The attack has reignited the debate about the security and practicality of storing bitcoin in hardware wallets.

"$2 on AI Defense" Could Have Prevented the Exploit — Dragonfly's Opinion

Approximately $2 spent on AI-powered code review could have prevented the Coldcard exploit — this is how Dragonfly managing partner Haseeb Qureshi commented on social media reports that some AI models detected the vulnerability in less than 20 minutes.

However, it is unlikely that AI models could have independently discovered this vulnerability before information about it became public.

Vulnerability in Private Key Generation

The growing capabilities of AI models are significantly reducing the cost and time required to discover new vulnerabilities in the cryptocurrency sphere. Meanwhile, the private key generation mechanism of the device itself may have played a role in the success of the Coldcard attack.

The private key entropy level of Coldcard was only 40 bits — noticeably lower than the standard adopted by other wallets, where a 12-word seed phrase provides 128 bits of entropy. This deviation from the accepted standard was the result of a firmware error, which significantly simplified the task for malicious actors.

The cost of discovering such vulnerabilities will continue to decrease as AI models' capabilities grow and their use becomes more widespread, both in cybersecurity and in conducting attacks.

The Coldcard attack remains one of the largest incidents in hardware wallet history: confirmed losses stand at $100 million, and with the fourth wave, could rise to $130 million. The involvement of more than 15 separate malicious actors shows how widely information about the vulnerability spread after its disclosure.

AI Opinion

From the perspective of machine data analysis, the Coldcard case resembles the story of the "Milk Sad" vulnerability discovered in 2023 in the Libbitcoin Explorer tool. At that time, the key generator limited entropy to just 32 bits instead of the required 256, allowing malicious actors to recover the private keys of thousands of wallets. The parallel is illustrative: the 40 bits of entropy in Coldcard exceed Libbitcoin's figure, but remain orders of magnitude below the standard 128 bits, meaning such firmware errors can recur in different products regardless of their reputation.

Related Questions

QHow many separate attackers exploited the Coldcard vulnerability, according to Galaxy Digital's Alex Thorn?

AMore than 15 separate attackers exploited the Coldcard vulnerability.

QWhat is the estimated total loss from the confirmed attack waves on Coldcard, according to Galaxy Research?

AThe estimated losses from the confirmed attack waves on Coldcard have reached $100 million.

QWhat key flaw in Coldcard's private key generation significantly aided the attackers?

AThe private key entropy for Coldcard was only 40 bits, which is significantly lower than the standard 128 bits provided by a 12-word seed phrase, making it much easier for attackers to brute-force.

QWhat parallel does the AI analysis in the article draw regarding the Coldcard vulnerability?

AThe AI analysis compares it to the 'Milk Sad' vulnerability found in 2023 in the Libbitcoin Explorer tool, where key generator entropy was limited to 32 bits instead of the required 256 bits.

QAccording to Dragonfly's Haseeb Qureshi, what could have potentially prevented the Coldcard exploit?

ASpending approximately $2 on AI-powered code review could have potentially prevented the Coldcard exploit, as some AI models reportedly identified the vulnerability in under 20 minutes.

Related Reads

"20CM" Limit Up: Another Star Secondary New Stock on the STAR Market?

On September 14th, the STAR Market's recently listed stock, Gaokai Technology, surged and hit the 20% daily limit, reaching a new all-time high of 324.41 yuan. The stock opened slightly higher and quickly rose to the limit-up price, closing with a full 20% gain. Its turnover reached approximately 1.128 billion yuan. Gaokai Technology went public on August 25, 2026, with an IPO price of 61.36 yuan. Its first-day closing price of 235.00 yuan represented a massive 282.99% surge from the IPO price. Following the recent 20% rise, the stock has gained about 4.29 times relative to its IPO price. The company, Jiangsu Gaokai Precision Fluid Technology Co., Ltd., is a national-level specialized and sophisticated "Little Giant" enterprise. It is a leader in China's precision fluid control sector, focusing on R&D, production, and sales of key control components. Its core products include flow control, dispensing/packaging, and precision coating systems, serving industries such as semiconductors, consumer electronics, and new energy. Financially, Gaokai has shown rapid growth. From 2023 to 2025, its operating revenue increased from 226 million yuan to 511 million yuan, with net profit attributable to parent shareholders rising sharply. In the first half of 2026, revenue grew 35.46% year-on-year to 327 million yuan, while net profit surged 95.07% to 106 million yuan. The stock's strong performance reflects market interest in semiconductor supply chain components and import substitution themes, as well as pricing for the growth potential of new listings. However, with a high trailing P/E ratio of approximately 175.79 and a relatively short trading history, investors should be mindful of potential volatility risks.

marsbit2h ago

"20CM" Limit Up: Another Star Secondary New Stock on the STAR Market?

marsbit2h ago

Trading

Spot
活动图片