A significant security incident affecting Coldcard hardware wallet users has grown substantially larger than initially reported, with new on-chain evidence suggesting attackers have compromised approximately 1,367 Bitcoin across multiple waves of coordinated fund transfers. Galaxy Research's latest analysis indicates the breach now spans three distinct phases of activity, each targeting thousands of affected addresses in what appears to be a methodical campaign rather than isolated exploits. The escalating damage figure—now approaching $88 million at current market valuations—underscores both the scale of the vulnerability and the operational sophistication of those executing the theft.
The expanding scope of the incident reveals a troubling pattern in how the attackers have operated. Rather than executing a single large-scale heist, the perpetrators have conducted multiple waves of sweeps targeting different cohorts of Coldcard users, suggesting either an ongoing vulnerability window or access to multiple vectors of compromise. This phased approach complicates immediate attribution and mitigation efforts, as it indicates the threat actors maintain persistent access or continue to exploit newly identified weak points in the wallet's security architecture. Each successive wave has drained funds from previously untouched addresses, demonstrating that the initial round of defensive measures taken by affected users and the broader community may have been insufficient to prevent continued losses.
On-chain monitoring has flagged two additional red flags that warrant close attention from the broader ecosystem. Exchange deposit activity has spiked noticeably as attackers attempt to convert stolen Bitcoin into fiat currency or other assets, creating a narrow window for exchanges to implement frozen account protocols and coordinate with law enforcement. Simultaneously, long-dormant Bitcoin wallets have begun moving funds—a phenomenon that typically attracts attention from market participants tracking wallet age cohorts and realized price distributions. These dual signals suggest either that some victims have only recently discovered their losses, or that attackers are accessing older, presumably less-monitored wallet addresses as part of their exit strategy.
The Coldcard incident serves as a sobering reminder that even established hardware wallet manufacturers remain vulnerable to sophisticated compromise, whether through supply chain attacks, firmware exploits, or social engineering campaigns targeting seed recovery. As investigators continue piecing together the technical forensics, the focus will likely shift toward determining whether this represents a localized failure specific to Coldcard or a systemic vulnerability that could affect other hardware wallet manufacturers operating under similar security assumptions. The industry's response to this breach may fundamentally reshape how users approach hardware wallet security protocols and how manufacturers disclose potential threats.