At least 15 attackers exploited Coldcard vulnerability: Galaxy

cointelegraphОпубліковано о 2026-08-04Востаннє оновлено о 2026-08-04

Анотація

At least 15 attackers have exploited a vulnerability in Coldcard hardware wallets, leading to estimated losses of up to $130 million in Bitcoin across multiple attack waves. According to Galaxy Digital, the exploitation method differed from typical exchange hacks, with one minor theft report uncovering a larger attack. The incident has sparked debate on cold wallet security. Some, like Dragonfly's Haseeb Qureshi, suggest inexpensive AI-based security hardening could have prevented the breach, citing reports that AI models quickly identified the flaw. However, analysts caution these claims lack rigorous testing and note the vulnerability was public before AI assessment. The weakness reportedly involved lower-than-standard private key entropy due to a firmware bug. Experts warn that advancing AI capabilities are reducing the cost and time to find such cryptocurrency vulnerabilities.

At least 15 different attackers have exploited the Coldcard vulnerability, according to Galaxy Digital’s head of research, Alex Thorn, citing new victim reports received since the incident.

Thorn said Tuesday that the victim reports helped the company label new attackers that would have gone undiscovered, as the nature of the exploit was different from a hack on a centralized exchange.

“Due to one single victim’s report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses,” Thorn wrote in a Tuesday X post.

The estimated losses from the Coldcard exploit have grown to $100 million across three confirmed attack waves, according to Galaxy Research. The company also identified a suspected fourth wave that could bring total losses to about $130 million in Bitcoin (BTC).

The ongoing attack reignited debate about the security of cold storage wallets and whether users are safer by holding their own Bitcoin.

$2 worth of AI hardening could have prevented the exploit: Dragonfly partner

Roughly “$2 of AI hardening” could have prevented the Coldcard exploit, wrote Dragonfly managing partner Haseeb Qureshi, citing social media reports that some AI models rediscovered the vulnerability that led to the attack in less than 20 minutes.

Qureshi’s remarks came in response to multiple social media users claiming that Claude was able to regenerate the vulnerability in just eight minutes. He argued that these results may have been contaminated by web search and added that open-source AI model GLM 5.2 was able to rediscover the attack in 20 minutes with web access turned off.

However, it is unlikely that AI models would have independently discovered this vulnerability before it was made public, crypto analytics platform Tokenomist’s data lead, Tatsapat Saerejittima, told Cointelegraph. He said:

“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.”

Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says

Vulnerability seen in private key setup

Crypto research company Castle Labs’ co-founder, Francesco, said that the growing capabilities of AI models are drastically reducing the cost and time it takes to discover new cryptocurrency vulnerabilities, but added that Coldcard’s private key may have played a role in the vulnerability.

Coldcard used a “level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug, making the job easier,” he told Cointelegraph.

Francesco, who asked that Cointelegraph not use his last name, said he expects the cost of bug discovery to continue decreasing as AI models gain more capabilities and become more prominent in both cybersecurity and exploits.

Magazine: Does Botanix’s failure prove Bitcoiners don’t care about DeFi?

Пов'язані питання

QHow many different attackers have exploited the Coldcard vulnerability according to Galaxy Digital's head of research?

AAt least 15 different attackers have exploited the Coldcard vulnerability.

QWhat is the estimated total loss from the Coldcard exploit according to Galaxy Research, and what could the total rise to with a suspected fourth wave?

AThe estimated losses have grown to $100 million across three confirmed attack waves, and a suspected fourth wave could bring total losses to about $130 million.

QAccording to Dragonfly's managing partner, what could have prevented the Coldcard exploit, and based on what social media reports?

ARoughly $2 of AI hardening could have prevented the exploit, based on social media reports that some AI models rediscovered the vulnerability in less than 20 minutes.

QWhat specific technical aspect of Coldcard's setup did Francesco from Castle Labs suggest may have played a role in the vulnerability?

AHe suggested that Coldcard used a level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug.

QWhat debate did the ongoing Coldcard attack reignite?

AThe attack reignited debate about the security of cold storage wallets and whether users are safer by holding their own Bitcoin.

Пов'язані матеріали

Michael Saylor: Bitcoin Halved, My Digital Credit is Making Money

Michael Saylor discusses Bitcoin, digital credit, and corporate treasury strategies in a recent roundtable. He explains that while Bitcoin remains "digital capital" with no counterparty risk, its ~40% annual volatility makes it unsuitable for most institutional and retail capital. To attract this capital, he advocates for Bitcoin-backed "digital credit" and "digital currency" products. These offer low volatility against fiat currencies, generate yield, and compete with traditional money market funds, stablecoins, and other yield-bearing crypto assets. Saylor clarifies that these products are not meant to replace direct Bitcoin ownership but to onboard capital that otherwise wouldn't enter the Bitcoin ecosystem. He provides examples: during a period when Bitcoin fell 50%, his company's digital credit products (STRC, SATA) delivered positive returns of 3-4%, demonstrating their ability to strip out ~90% of Bitcoin's volatility. He frames "digital currency" as a fiat-referenced, yield-bearing, stable-value asset backed by Bitcoin, designed to meet the needs of the global capital pool. This approach, he argues, can expand the Bitcoin network's reach by 10x to 100x more effectively than pure education. The discussion also covers corporate finance for Bitcoin treasury companies. Saylor argues that equity issuance is not inherently dilutive if done above net asset value per share and if the acquired asset (Bitcoin or cash) supports future value creation. He distinguishes between debt with maturity dates and hybrid capital like preferred shares (e.g., STRC), which offer issuer options and do not force liquidation. Evaluating these companies requires modeling based on future Bitcoin price and volatility assumptions, not relying on a single metric like mNAV (market-adjusted net asset value). The business models are still evolving, and investors must analyze full disclosures to form a complete view.

marsbit2 год тому

Michael Saylor: Bitcoin Halved, My Digital Credit is Making Money

marsbit2 год тому

Getting Ahead of the Tide and Drowning First: The Fall of 'Crypto x AI' Pioneer ai16z

"ai16z, an early pioneer of the 'crypto x AI' narrative, has officially shut down. In late 2024, its token launch sparked a massive speculative frenzy around AI Agent tokens, briefly propelling the project to a $2.6 billion valuation. However, by 2026, as functional AI agents from companies like Anthropic and OpenAI became mainstream reality, the crypto-native AI projects built largely on hype began to collapse. The founder of its underlying project, Eliza OS, announced the termination in a bitter post, citing legal threats from token holders and a depleted foundation. He expressed disillusionment with the crypto community, contrasting it with the 'optimistic' builders in pure AI. While the Eliza framework itself remains active as open-source software—ironically with contributions from AI like Claude—the token-dependent venture failed. The story highlights a core flaw: the crypto market often prices narratives far ahead of functional technology. When the promised AI future arrived, it was delivered by traditional tech companies with sustainable business models, not token projects. The episode suggests the initial path of 'tokenizing AI concepts' is broken. However, integration may still occur in reverse—with AI tools enhancing crypto analytics and trading—or in coordinating real resources like decentralized compute, as seen in projects like Bittensor and Render."

marsbit2 год тому

Getting Ahead of the Tide and Drowning First: The Fall of 'Crypto x AI' Pioneer ai16z

marsbit2 год тому

Торгівля

Спот
活动图片