A suspected fourth wave of attacks targeting Coldcard hardware wallets has reportedly compromised approximately 389 Bitcoin, according to research from Galaxy Digital's head analyst Alex Thorn. The incident underscores a persistent vulnerability in one of the cryptocurrency industry's most trusted cold storage solutions, raising fresh questions about the security assumptions surrounding even air-gapped devices. While the exact technical vector remains under investigation, the pattern of repeated compromises suggests either a fundamental design flaw or a sophisticated supply-chain vulnerability that multiple security audits have thus far failed to catch.
Thorn's analysis indicates that affected users may have a narrow window to recover their assets, leveraging the mempool state to intercept or redirect unconfirmed transactions before they settle on-chain. This recovery mechanism relies on transaction malleability and timing precision—users would need to broadcast replacement transactions with higher fees before attackers confirm their own transfers. However, this approach only works if users actively monitor their wallets and retain some degree of access to their signing keys or recovery mechanisms. For victims who have already lost control of their devices, this window closes rapidly once blocks confirm the theft, making early detection and intervention critical.
The Coldcard incidents fit a broader pattern of hardware wallet compromises that have accumulated throughout 2023 and 2024, suggesting that physical security alone is insufficient protection against determined adversaries. Whether the attacks stem from firmware exploitation, side-channel attacks during manufacturing, or intercepted devices modified before shipment, the cumulative effect has been to shake confidence in the device's threat model. Galaxy's research serves as a reminder that even devices marketed as disconnected from internet infrastructure remain vulnerable to determined attackers with sufficient resources or insider access. The hardware wallet industry has historically marketed these devices as the gold standard for self-custody, yet repeated incidents demonstrate that operational security, key management practices, and supply-chain integrity matter as much as the underlying cryptography.
Moving forward, users holding significant Bitcoin positions should consider whether multi-signature schemes across different device types, geographic key distribution, or even institutional custodial services might offer better risk-adjusted security profiles than relying on a single hardware wallet manufacturer.