15 Malicious Actors Exploited Coldcard Hardware Wallet Vulnerability

cryptonews.ruОпубліковано о 2026-08-05Востаннє оновлено о 2026-08-05

Анотація

More than 15 distinct malicious actors exploited a vulnerability in the Coldcard hardware wallet, according to Alex Thorn of Galaxy Digital. Analysis of victim reports, including one involving the theft of under 1 BTC, led to the discovery of an attack that drained 12 BTC from 126 addresses. The estimated losses from this exploit have reached $100 million across three confirmed attack waves, with a potential fourth wave possibly raising total losses to around $130 million in Bitcoin. The incident has reignited debate about the security of cold storage. Notably, Haseeb Qureshi of Dragonfly suggested that spending roughly $2 on AI-powered code auditing could have potentially prevented the exploit, as some AI models reportedly identified the vulnerability in under 20 minutes post-disclosure. The core flaw was a critical reduction in private key entropy within the device's firmware. Instead of the standard 128 bits of entropy provided by a 12-word seed phrase, Coldcard's key generation was limited to just 40 bits, significantly simplifying the task for attackers. This case draws parallels to the 2023 "Milk Sad" vulnerability in Libbitcoin Explorer, highlighting how firmware errors compromising entropy can repeat across different products. The widespread exploitation by over 15 parties underscores how quickly vulnerability information spreads after disclosure.

More than 15 separate malicious actors exploited the Coldcard vulnerability — this assessment was given by Alex Thorn, Head of Research at Galaxy Digital, based on new reports from victims. Thorn posted on social media X that victims' complaints helped the company identify attackers who would otherwise have remained undetected: the nature of this exploit differs from hacking a centralized exchange.

"Thanks to a single victim's report of a theft of less than 1 $BTC, we discovered a new attack that resulted in 12 $BTC being drained from 126 addresses," wrote Thorn.

The estimated losses from the Coldcard exploit have risen to $100 million across three confirmed attack waves, according to Galaxy Research. A fourth wave has also been identified, potentially bringing total losses to around $130 million in bitcoin.

The attack has reignited the debate about the security and practicality of storing bitcoin in hardware wallets.

"$2 on AI Defense" Could Have Prevented the Exploit — Dragonfly's Opinion

Approximately $2 spent on AI-powered code review could have prevented the Coldcard exploit — this is how Dragonfly managing partner Haseeb Qureshi commented on social media reports that some AI models detected the vulnerability in less than 20 minutes.

However, it is unlikely that AI models could have independently discovered this vulnerability before information about it became public.

Vulnerability in Private Key Generation

The growing capabilities of AI models are significantly reducing the cost and time required to discover new vulnerabilities in the cryptocurrency sphere. Meanwhile, the private key generation mechanism of the device itself may have played a role in the success of the Coldcard attack.

The private key entropy level of Coldcard was only 40 bits — noticeably lower than the standard adopted by other wallets, where a 12-word seed phrase provides 128 bits of entropy. This deviation from the accepted standard was the result of a firmware error, which significantly simplified the task for malicious actors.

The cost of discovering such vulnerabilities will continue to decrease as AI models' capabilities grow and their use becomes more widespread, both in cybersecurity and in conducting attacks.

The Coldcard attack remains one of the largest incidents in hardware wallet history: confirmed losses stand at $100 million, and with the fourth wave, could rise to $130 million. The involvement of more than 15 separate malicious actors shows how widely information about the vulnerability spread after its disclosure.

AI Opinion

From the perspective of machine data analysis, the Coldcard case resembles the story of the "Milk Sad" vulnerability discovered in 2023 in the Libbitcoin Explorer tool. At that time, the key generator limited entropy to just 32 bits instead of the required 256, allowing malicious actors to recover the private keys of thousands of wallets. The parallel is illustrative: the 40 bits of entropy in Coldcard exceed Libbitcoin's figure, but remain orders of magnitude below the standard 128 bits, meaning such firmware errors can recur in different products regardless of their reputation.

Пов'язані питання

QHow many separate attackers exploited the Coldcard vulnerability, according to Galaxy Digital's Alex Thorn?

AMore than 15 separate attackers exploited the Coldcard vulnerability.

QWhat is the estimated total loss from the confirmed attack waves on Coldcard, according to Galaxy Research?

AThe estimated losses from the confirmed attack waves on Coldcard have reached $100 million.

QWhat key flaw in Coldcard's private key generation significantly aided the attackers?

AThe private key entropy for Coldcard was only 40 bits, which is significantly lower than the standard 128 bits provided by a 12-word seed phrase, making it much easier for attackers to brute-force.

QWhat parallel does the AI analysis in the article draw regarding the Coldcard vulnerability?

AThe AI analysis compares it to the 'Milk Sad' vulnerability found in 2023 in the Libbitcoin Explorer tool, where key generator entropy was limited to 32 bits instead of the required 256 bits.

QAccording to Dragonfly's Haseeb Qureshi, what could have potentially prevented the Coldcard exploit?

ASpending approximately $2 on AI-powered code review could have potentially prevented the Coldcard exploit, as some AI models reportedly identified the vulnerability in under 20 minutes.

Пов'язані матеріали

Торгівля

Спот
活动图片