Coldcard Vulnerability Exploited by 15+ Attackers, $100M Stolen
Galaxy Research reveals at least 15 attackers exploited a firmware bug in Coldcard wallets, siphoning $100 million in Bitcoin across three waves, with a suspected fourth wave pushing losses to $130 million.
Quick Take
A Coldcard firmware bug reduced private key entropy to 40 bits, enabling brute-force attacks.
Estimated losses exceed $100 million across three attack waves, with a fourth wave likely.
Debate erupts over cold storage security and AI's role in discovering vulnerabilities.
One victim report of less than 1 BTC exposed a new attack vector stealing 12 BTC from 126 addresses.
Market Impact Analysis
BearishMajor exploit of a popular hardware wallet undermines trust in cold storage, potentially causing panic selling and negative sentiment for Bitcoin.
Speculation Analysis
Key Takeaways
- At least 15 attackers exploited a Coldcard firmware bug that used only 40-bit entropy—enabling brute-force theft of over $100 million in Bitcoin.
- A fourth attack wave is suspected, potentially pushing total losses to $130 million and further eroding confidence in hardware wallet security.
- One victim's report of a sub-1 BTC theft uncovered a new attack vector: 12 BTC drained from 126 addresses in a single sweep.
- The breach reignites the cold storage debate as AI models can now rediscover such vulnerabilities in under 20 minutes.
What Happened
A firmware bug in Coldcard hardware wallets generated Bitcoin private keys with only 40 bits of entropy—drastically weaker than the industry-standard 128 bits. This flaw made brute-force attacks practical, and at least 15 separate attackers seized the opportunity. Galaxy Research tracked three distinct theft waves, with estimated losses exceeding $100 million. A fourth wave is now suspected, which could push the total haul to $130 million. The discovery of a new attack path—where 12 BTC vanished from 126 addresses after one victim reported a tiny theft—shows the exploit's evolving nature. The incident has shaken the crypto community's faith in cold storage, long considered the gold standard for self-custody.
The Numbers
The breach's scale is staggering: over $100 million in BTC stolen across three waves, with a potential fourth wave adding another $30 million. One particularly audacious attack drained 12 BTC from 126 addresses, triggered by a victim's report of losing less than 1 BTC. Coldcard's flawed firmware generated keys with just 40 bits of entropy, whereas a standard 12-word seed provides 128 bits. AI models like Claude and open-source GLM 5.2 reportedly rediscovered the vulnerability in under 20 minutes, even without web search, highlighting how trivially the weakness could now be found.
Why It Happened
The root cause was a firmware defect that slashed Coldcard's key entropy to 40 bits. This made private keys predictable enough for brute-force cracking—a catastrophic failure for a device meant to secure assets offline. The bug persisted undetected until attackers exploited it, underscoring gaps in hardware wallet auditing. Once public, AI systems demonstrated the vulnerability's simplicity by reconstructing it in minutes, though experts caution that no blind tests were conducted. The attack vector suggests off-chain key compromise, proving that even air-gapped devices are not invulnerable if their core cryptography is broken.
Broader Impact
The Coldcard exploit cracks the perception of hardware wallets as impenetrable. Trust in cold storage may erode, driving users back to exchange custody or novel multi-signature setups. Regulators will likely intensify scrutiny of wallet manufacturers, demanding rigorous entropy audits. The incident also spotlights AI's double-edged role: while it can rapidly expose flaws, proactive use by developers could prevent such disasters. For the broader market, the breach could trigger short-term bearish sentiment as confidence in Bitcoin self-custody wavers.
What to Watch Next
- Whether the suspected fourth attack wave materializes and swells losses to $130 million.
- Coldcard's official response, potential firmware patches, and any legal or regulatory fallout.
- Adoption of formal verification and AI-assisted audits across hardware wallet firms to prevent similar bugs.
This article is for informational purposes only and does not constitute financial advice.
Always late to trends?
Join for the latest news, insights & more.
Disclaimer: Bytewit is an independent media outlet that delivers news, research, and data.
© 2026 Bytewit. All Rights Reserved. This article is for informational purposes only.