At least 15 attackers exploited Coldcard vulnerability: Galaxy

cointelegraphPublicado a 2026-08-04Actualizado a 2026-08-04

Resumen

At least 15 attackers have exploited a vulnerability in Coldcard hardware wallets, leading to estimated losses of up to $130 million in Bitcoin across multiple attack waves. According to Galaxy Digital, the exploitation method differed from typical exchange hacks, with one minor theft report uncovering a larger attack. The incident has sparked debate on cold wallet security. Some, like Dragonfly's Haseeb Qureshi, suggest inexpensive AI-based security hardening could have prevented the breach, citing reports that AI models quickly identified the flaw. However, analysts caution these claims lack rigorous testing and note the vulnerability was public before AI assessment. The weakness reportedly involved lower-than-standard private key entropy due to a firmware bug. Experts warn that advancing AI capabilities are reducing the cost and time to find such cryptocurrency vulnerabilities.

At least 15 different attackers have exploited the Coldcard vulnerability, according to Galaxy Digital’s head of research, Alex Thorn, citing new victim reports received since the incident.

Thorn said Tuesday that the victim reports helped the company label new attackers that would have gone undiscovered, as the nature of the exploit was different from a hack on a centralized exchange.

“Due to one single victim’s report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses,” Thorn wrote in a Tuesday X post.

The estimated losses from the Coldcard exploit have grown to $100 million across three confirmed attack waves, according to Galaxy Research. The company also identified a suspected fourth wave that could bring total losses to about $130 million in Bitcoin (BTC).

The ongoing attack reignited debate about the security of cold storage wallets and whether users are safer by holding their own Bitcoin.

$2 worth of AI hardening could have prevented the exploit: Dragonfly partner

Roughly “$2 of AI hardening” could have prevented the Coldcard exploit, wrote Dragonfly managing partner Haseeb Qureshi, citing social media reports that some AI models rediscovered the vulnerability that led to the attack in less than 20 minutes.

Qureshi’s remarks came in response to multiple social media users claiming that Claude was able to regenerate the vulnerability in just eight minutes. He argued that these results may have been contaminated by web search and added that open-source AI model GLM 5.2 was able to rediscover the attack in 20 minutes with web access turned off.

However, it is unlikely that AI models would have independently discovered this vulnerability before it was made public, crypto analytics platform Tokenomist’s data lead, Tatsapat Saerejittima, told Cointelegraph. He said:

“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.”

Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says

Vulnerability seen in private key setup

Crypto research company Castle Labs’ co-founder, Francesco, said that the growing capabilities of AI models are drastically reducing the cost and time it takes to discover new cryptocurrency vulnerabilities, but added that Coldcard’s private key may have played a role in the vulnerability.

Coldcard used a “level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug, making the job easier,” he told Cointelegraph.

Francesco, who asked that Cointelegraph not use his last name, said he expects the cost of bug discovery to continue decreasing as AI models gain more capabilities and become more prominent in both cybersecurity and exploits.

Magazine: Does Botanix’s failure prove Bitcoiners don’t care about DeFi?

Preguntas relacionadas

QHow many different attackers have exploited the Coldcard vulnerability according to Galaxy Digital's head of research?

AAt least 15 different attackers have exploited the Coldcard vulnerability.

QWhat is the estimated total loss from the Coldcard exploit according to Galaxy Research, and what could the total rise to with a suspected fourth wave?

AThe estimated losses have grown to $100 million across three confirmed attack waves, and a suspected fourth wave could bring total losses to about $130 million.

QAccording to Dragonfly's managing partner, what could have prevented the Coldcard exploit, and based on what social media reports?

ARoughly $2 of AI hardening could have prevented the exploit, based on social media reports that some AI models rediscovered the vulnerability in less than 20 minutes.

QWhat specific technical aspect of Coldcard's setup did Francesco from Castle Labs suggest may have played a role in the vulnerability?

AHe suggested that Coldcard used a level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug.

QWhat debate did the ongoing Coldcard attack reignite?

AThe attack reignited debate about the security of cold storage wallets and whether users are safer by holding their own Bitcoin.

Lecturas Relacionadas

Sui Transfers $65 Billion for Free. Its Co-founder Is Confident Even Grander Things Are Ahead

Sui's co-founder Evan Cheng makes a radical prediction: within four years, digital payment volume on the Sui blockchain will rival that of traditional card networks and banking systems. This claim is ambitious for an L1 blockchain whose token trades just above $0.60. Cheng, CEO of Sui's developer Mysten Labs, frames Sui's roadmap as an infrastructure play, not a trading platform. He believes current Web3 infrastructure is stuck in an "era of dial-up access." Founded by ex-Meta engineers behind the Diem blockchain and Move programming language, Mysten Labs envisions Sui as a "communication system" for stablecoin settlements, remittances, and future AI-to-AI commerce. Co-founder Adeniyi Abiodun adds that the internet will soon enable free, private, large-scale payments as privacy features roll out on Sui. The vision is backed by data. Since Mysten Labs eliminated gas fees for stablecoin transfers at the protocol level in June, Sui has processed over $65 billion in stablecoin transfers. Having handled $2.27 trillion in stablecoin volume since early 2024, this move removes a major barrier by not requiring merchants to hold a second asset for fees. Sui is also encroaching on Bitcoin's territory with the Hashi testnet, allowing Bitcoin to be used as DeFi collateral on Sui without converting to a synthetic token. Furthermore, a default privacy feature for stablecoin transactions is in development, cited by institutions as crucial for moving real payment volume to public blockchains. Skeptics point to Sui's token facing sell pressure from unlock schedules and its $2.8B market cap being a fraction of the payment volumes Cheng cites. Whether Sui becomes the "rail for every internet payment" or captures a smaller but significant share of stablecoin and cross-border settlements remains to be seen. The coming year's gas-free transaction data and Hashi bridge adoption will test if Cheng's four-year forecast is realistic or founder-driven optimism.

cryptonews.ruHace 29 min(s)

Sui Transfers $65 Billion for Free. Its Co-founder Is Confident Even Grander Things Are Ahead

cryptonews.ruHace 29 min(s)

Trading

Spot
活动图片