Curious about today's AI digest?ai-tldr.dev

Daily Digest

Coldcard Exploit: Galaxy Research Raises Confirmed Losses to 1,719 BTC

TechnologyMAJOR54m ago5 min read
Share
Coldcard Exploit: Galaxy Research Raises Confirmed Losses to 1,719 BTC

Galaxy Research revised the Coldcard exploit tally Saturday to 1,719 BTC — roughly $111 million — as a five-year-old firmware flaw continues to generate new victim reports, with the revised tally expected to climb further.

  • Galaxy Research confirmed 1,719 BTC ($111M) stolen in the ongoing Coldcard exploit, with total losses projected to exceed $130M.
  • A March 2021 firmware defect cut seed entropy from 128 to ~72 bits, letting attackers reconstruct keys without physical device access.
  • 250+ victims have filed reports with Galaxy Research; at least 15 distinct threat actors have been identified across three attack waves.

Lead

Galaxy Research on Saturday, August 8, raised its confirmed Coldcard exploit figure to 1,719 BTC, or approximately $111 million at current prices, following a new batch of victim disclosures. The research group flagged total losses — including wallets not yet fully documented — as likely surpassing $130 million, making the incident the largest hardware wallet breach on record and the third-largest crypto theft of 2026. The number of individuals who have contacted Galaxy directly now exceeds 250 victims, spanning retail holders across multiple continents.

What Happened

The root cause is a build-configuration error in a Coinkite firmware update shipped March 17, 2021. Devices running affected versions — 4.0.1 through 4.1.9 on the Coldcard Mk3, Mk4, Mk5, and Q lines — silently substituted a software random-number generator for the hardware entropy source during seed creation. The result: recovery seeds carrying roughly 72 bits of effective randomness rather than the 128 bits the design specified. Attackers precomputed the truncated keyspace offline, requiring no physical access to a device once the seed generation window was identified on-chain.

The exploit unfolded in three documented waves. On July 30, within 41 minutes, roughly 1,083 BTC was swept from 1,196 addresses, a pace that pointed to full automation. Subsequent waves through August 3 brought the observed tally to approximately 1,367 BTC across 4,585 addresses. Saturday's revised tally of 1,719 BTC incorporates new address clusters linked to the same seed-entropy flaw and victim-reported transaction IDs submitted through Galaxy's disclosure portal.

Attack Profile

Galaxy Research has identified at least 15 distinct threat actors operating independently within the same exploitable keyspace. The fragmented attacker structure — more than 25 documented attack patterns — suggests the precomputed seed tables circulated beyond a single group after the vulnerability became known. Victim profiles skew toward everyday Bitcoin holders rather than institutional custodians, consistent with the retail market segment that adopted Coldcard Mk4 and Mk5 hardware in 2021–2023.

Industry Response

Coinkite moved to deprecate affected firmware builds and publicly urged users to sweep funds to wallets generated on unaffected hardware or clean software implementations. On-chain messaging to attacker-controlled addresses from distressed holders has been visible across several Bitcoin block explorers. A community-organized reimbursement pool, proposed by Stacks co-founder Muneeb Ali, would allow Bitcoin holders to purchase victim claims at face value, though the initiative remains in early coordination.

Security researchers at TRM Labs confirmed the exploit vectors align with known weak-entropy attack methodologies documented in academic literature since 2018, noting that the five-year gap between firmware release and active exploitation likely reflects time needed to build sufficiently complete precomputed tables.

Outlook

Galaxy Research has indicated additional victim clusters remain under analysis, and Saturday's 1,719 BTC figure is likely to see further upward revisions as the disclosure window remains open. The broader hardware wallet sector now faces intensified scrutiny of entropy-sourcing architecture, with independent auditors calling for mandatory entropy-validation routines in future firmware certification standards. Regulatory bodies in the European Union and the United Kingdom are monitoring the incident for potential implications under digital-asset consumer protection frameworks currently under legislative review.

The Daily Briefing

Every story that moved the market, every weekday.

AI-curated market news — the major stories only, free, and one email a day.

One email a day. Unsubscribe anytime.

Gain deeper insights from your reading