Skip to content

Coldcard Losses Climb Past $130 Million as a Fourth Wave of Thefts Hits Self-Custody Wallets

Galaxy Research now counts more than 5,200 drained addresses since the firmware flaw Blockhead first reported on August 3, and Coinkite's CEO says AI-assisted code review may be why it was finally found

Table of Contents

The Coldcard hardware wallet exploit we first covered on August 3 has kept growing, with Galaxy Research now tracking roughly 2,055 bitcoin, worth about $130 million at current prices, drained across three confirmed waves and a suspected fourth.

The underlying flaw hasn't changed since Coinkite's initial disclosure: a March 2021 firmware update silently routed wallet seed generation through a predictable software fallback instead of the device's dedicated hardware random number generator, collapsing the effective key strength from a designed 128 bits down to as little as 40 bits on older devices — low enough to brute-force without ever touching the physical wallet.

What has changed is the scale. The first confirmed sweep, on July 30, took 1,082.65 BTC from 1,196 addresses in 41 minutes. By this week, TRM Labs and Galaxy Research had tracked the theft across more than 5,200 addresses, with a fourth wave still unconfirmed. Roughly 90% of the stolen bitcoin has not moved since landing in the attackers' wallets, according to Galaxy.

Coinkite CEO Rodolfo Novak has offered an explanation for why a five-year-old bug surfaced now rather than earlier: he believes an attacker used AI-assisted code review to find the flaw faster than Coldcard's own auditors or the broader security research community had managed to in half a decade. Wallets generated using the device's dice-roll entropy option, which lets users supply their own physical randomness during setup, are unaffected. Coinkite has not offered compensation to victims and continues urging all other Coldcard users to migrate to freshly generated seeds on updated firmware.

The exploit has reignited a long-running debate in crypto that Blockhead has tracked from multiple angles this year: whether self-custody, done by the book, is actually safer than trusting a regulated third party with institutional-grade security architecture. One widely shared account from an affected user, who said his device had never touched the internet and sat in a bank safety deposit box, captured the unease driving that debate — a hardware wallet is supposed to solve exactly the failure mode it just suffered.

That contrast showed up directly in Blockhead's own coverage this week. In an unrelated story about BitGo CEO Mike Belshe wagering 100 BTC against Anthropic's Claude, the wallet at stake sits inside BitGo's institutional custody infrastructure, which splits signing authority across multiple keys using multi-party computation rather than depending on a single device or credential. The Coldcard exploit is close to a natural experiment in the opposite architecture: a single hardware device, a single point of seed generation, and a five-year-old software bug quietly waiting to be found.

Whether the incident meaningfully shifts institutional or high-net-worth demand from self-custody hardware toward MPC-based custodians is the open question the next few months should start to answer.

Latest