Galaxy: At Least 15 Actors Exploited Coldcard Flaw; Bitcoin Losses Could Approach $130M

AI Market Summary
Galaxy Digital reports at least 15 distinct attackers exploited a Coldcard hardware-wallet vulnerability that cut seed entropy to ~40 bits, enabling independent brute-force thefts. Confirmed losses are ~ $100M across three waves, with a suspected fourth lifting totals toward $130M in BTC, implying the event is still being reconstructed. The breadth of compromise and renewed AI-assisted discovery debate undermines self-custody confidence and heightens security and reputational risk across Bitcoin storage.
Impact level
● High
Affected assets
BTC/USDT+0.89%
AI Insight · BTC/USDTAI Insight
▼ Bearish
Trade now
⚠️ AI-generated insights are based on news content and are provided for informational purposes only. They do not constitute investment advice or represent the views of BingX. Investing involves risk. Please trade responsibly.
Galaxy Digital says it has identified at least 15 distinct attackers who took advantage of a Coldcard hardware-wallet vulnerability, after additional victim disclosures surfaced thefts that had not previously been linked to the incident. According to Galaxy, newly filed reports have helped analysts attribute separate attack patterns that would have remained invisible in a typical single-point exchange breach. With compromised wallet seeds usable independently, multiple actors can drain funds without coordination, complicating attribution, victim counts and total-loss estimates. Alex Thorn said even small complaints can illuminate broader activity. In one example, a report involving less than 1 BTC stolen helped researchers connect the same technique to an incident that removed 12 BTC across 126 addresses. Galaxy now puts confirmed losses at roughly $100 million in Bitcoin across three waves of exploitation. The firm also flagged a suspected fourth wave that could lift aggregate losses to around $130 million, underscoring that the timeline and scope are still being reconstructed. The episode has also reignited debate over whether low-cost AI testing could have caught the firmware issue before release. Dragonfly managing partner Haseeb Qureshi argued that about $2 of AI-focused hardening might have prevented the vulnerability, citing demonstrations in which models reproduced the flaw within minutes. Researchers have challenged those claims, noting that some tests occurred after details were public and lacked blind evaluation, documented methodology and false-positive analysis. Separately, an open-source model reportedly identified the issue in about 20 minutes without web access, adding fuel to the discussion over realistic pre-disclosure detection. Castle Labs said the bug effectively reduced Coldcard private-key entropy to about 40 bits, far below the 128-bit security typically associated with a standard 12-word seed. The entropy collapse would materially lower brute-force effort, helping explain how numerous attackers could exploit affected seeds in parallel. The incident highlights a failure mode in which a hardware wallet's security assumptions hinge on entropy that firmware can silently weaken. As AI reduces the cost of code review for both defenders and criminals, the key question is whether wallet makers can harden releases fast enough to keep implementation errors from becoming scalable theft across long-dormant Bitcoin addresses.