Galaxy Research reports that over $115 million worth of bitcoin has been reported missing following a targeted exploit of Coldcard hardware wallets.
In a Sunday post on X, Galaxy Research confirmed it had interviewed more than 200 affected individuals to provide support and collect intelligence on the perpetrators.
The valuations referenced are based on bitcoin’s market price at the time of the theft.
Coldcard losses have exceeded $115M (based on the price when coins were stolen)
Galaxy Research has spoken with 200+ victims to support them and gather intelligence on the attackers
This thread contains additional charts and info pic.twitter.com/H2K141mugF
Initial theft activity was detected on July 31, targeting bitcoin held in Coinkite’s widely used Coldcard hardware wallets.
Coinkite, a Canadian firm, identified a firmware bug in Coldcard Mk3 devices dating back to version 4.0.1 released in March 2021. The flaw caused seed generation to default to a weak software-based pseudorandom number generator instead of the device’s hardware true random number generator, effectively enabling attackers to guess seed phrases.
The total of stolen funds has continued to grow as attackers target newer devices, despite warnings from Coinkite and other community members urging users to immediately transfer their assets.
Last week, Galaxy Research estimated that a minimum of 15 independent actors were exploiting the vulnerability.
Earlier Galaxy Research indicated that stolen coins typically remained undisturbed for approximately 3.5 years, and that roughly 88% of pilfered funds had been inactive for at least one year.
The firm continues to quantify the full scope of the breach, noting that total losses may surpass $130 million.
In the aftermath, numerous investors have begun relocating their holdings to alternative storage options, including centralized exchanges.
Coinkite acknowledged in a recent statement that the software bug ‘silently went unnoticed’ and that its potential impact expanded with each product release.
Shortly after the initial breach, the company urged affected users to update their firmware or immediately move funds off the Coldcard wallet.
Also Read
- Study Suggests AI Agents Account for Minimal Share of Crypto Payments
- EU Mandates 24-Hour Reporting for Exploited Vulnerabilities in Connected Crypto Wallets
- AMC CEO Denounces Robinhood’s Tokenized Shares as Undermining Investor Protections
- Ringgit Forecast to Trade in Narrow Band Near RM4.06-RM4.08 Next Week

