The escalating Coldcard security breach has evolved into one of the most significant hardware wallet compromises in recent memory. Galaxy Research's latest analysis confirms that attackers have successfully drained approximately 1,367 Bitcoin across 4,585 distinct addresses, representing cumulative losses now exceeding $88 million at current valuations. What began as an isolated incident has transformed into a sustained campaign, with a third wave of thefts indicating the vulnerability remains actively exploited weeks after initial discovery.

The scope of this attack challenges fundamental assumptions about hardware wallet security. Coldcard devices, manufactured by Coinkite, have long been regarded as among the most secure Bitcoin custody solutions available, particularly within the self-sovereignty community. The fact that attackers have compromised thousands of addresses suggests either a widespread firmware vulnerability, a supply chain compromise affecting devices in distribution, or a social engineering vector targeting users. The persistence of the draining—now spanning multiple waves—indicates that attackers retain ongoing access to affected private keys or have identified a systematic method to extract them from what should be an air-gapped environment.

What distinguishes this incident from typical exchange hacks or smart contract exploits is the direct targeting of individual users who made explicit custody decisions. Hardware wallet users typically operate under the assumption that their devices isolate private keys from networked systems entirely. The involvement of 4,585 addresses suggests either widespread device compromise or a coordinated targeting of a specific user cohort who share a common vector of vulnerability. Initial investigations have pointed to potential firmware tampering or exploitation of the device's authentication mechanisms, though Coinkite has not yet provided comprehensive technical disclosure of the attack methodology.

The third wave designation from Galaxy Research carries significant weight: it implies attackers are continuing to discover additional vulnerable wallets rather than simply depleting a finite set of initially compromised devices. This pattern suggests the vulnerability may be exploitable across a broader class of Coldcard models or firmware versions than initially understood. The incident underscores a critical tension in hardware wallet design—the trade-off between convenience features and absolute isolation. Every additional interface or capability added to these devices, from firmware updates to optional connectivity features, potentially expands the attack surface.

For the broader Bitcoin self-custody ecosystem, this breach demands urgent technical forensics and threatens to reshape user confidence in device-based security models during a period when institutional adoption was accelerating.