More than 15 separate malicious actors exploited the Coldcard vulnerability — this assessment was given by Alex Thorn, Head of Research at Galaxy Digital, based on new reports from victims. Thorn posted on social media X that victims' complaints helped the company identify attackers who would otherwise have remained undetected: the nature of this exploit differs from hacking a centralized exchange.
"Thanks to a single victim's report of a theft of less than 1 $BTC, we discovered a new attack that resulted in 12 $BTC being drained from 126 addresses," wrote Thorn.
The estimated losses from the Coldcard exploit have risen to $100 million across three confirmed attack waves, according to Galaxy Research. A fourth wave has also been identified, potentially bringing total losses to around $130 million in bitcoin.
The attack has reignited the debate about the security and practicality of storing bitcoin in hardware wallets.
"$2 on AI Defense" Could Have Prevented the Exploit — Dragonfly's Opinion
Approximately $2 spent on AI-powered code review could have prevented the Coldcard exploit — this is how Dragonfly managing partner Haseeb Qureshi commented on social media reports that some AI models detected the vulnerability in less than 20 minutes.
However, it is unlikely that AI models could have independently discovered this vulnerability before information about it became public.
Vulnerability in Private Key Generation
The growing capabilities of AI models are significantly reducing the cost and time required to discover new vulnerabilities in the cryptocurrency sphere. Meanwhile, the private key generation mechanism of the device itself may have played a role in the success of the Coldcard attack.
The private key entropy level of Coldcard was only 40 bits — noticeably lower than the standard adopted by other wallets, where a 12-word seed phrase provides 128 bits of entropy. This deviation from the accepted standard was the result of a firmware error, which significantly simplified the task for malicious actors.
The cost of discovering such vulnerabilities will continue to decrease as AI models' capabilities grow and their use becomes more widespread, both in cybersecurity and in conducting attacks.
The Coldcard attack remains one of the largest incidents in hardware wallet history: confirmed losses stand at $100 million, and with the fourth wave, could rise to $130 million. The involvement of more than 15 separate malicious actors shows how widely information about the vulnerability spread after its disclosure.
AI Opinion
From the perspective of machine data analysis, the Coldcard case resembles the story of the "Milk Sad" vulnerability discovered in 2023 in the Libbitcoin Explorer tool. At that time, the key generator limited entropy to just 32 bits instead of the required 256, allowing malicious actors to recover the private keys of thousands of wallets. The parallel is illustrative: the 40 bits of entropy in Coldcard exceed Libbitcoin's figure, but remain orders of magnitude below the standard 128 bits, meaning such firmware errors can recur in different products regardless of their reputation.





