Approximately $130 million in Bitcoin losses are estimated following a series of attacks exploiting vulnerabilities within Coinkite’s Coldcard hardware wallets. Galaxy Research has put the potential total loss at 2,000 BTC (around $130 million), stemming from multiple attack waves. The firm identified issues originating in firmware versions of the Coldcard Mk3, Mk4, Mk5 and Coldcard Q devices.
The attacks unfolded over three confirmed waves, with 1,596 BTC reportedly stolen from 7,300 addresses. Further investigations revealed fourteen smaller security incidents associated with the compromised hardware wallets. Coinkite responded by releasing emergency firmware updates for all affected models and destroyed remaining vulnerable inventory.
Law enforcement agencies, including U.S. federal bodies, are collaborating with Galaxy Research and cyber investigation groups to trace the attacks. Crypto exchanges and the teams involved in these investigations continue to monitor activity concerning the stolen assets. According to reports, the attacks appear automated, potentially utilising large language model assistance.
Alex Thorn, Head of Firmwide Research at Galaxy Research, is leading efforts to identify potential Wave 4 attacks. He is collaborating with law enforcement bodies. Analysis indicates that 90% of the coins stolen in Waves 1, 2 and 3 have remained inactive while 100% of those funds moved in Waves 1, 2 and 3 remain static. The potential for a fourth wave of attacks has not been confirmed, with total potential losses reaching an estimated 2,055 BTC, though this figure remains unverified.
Further complicating the situation is the suspected involvement of a single entity behind Wave 4, allegedly “substantially comprised of” the attack. Confirmation regarding specific victims within this wave is currently lacking. There are concerns about new, opportunistic attackers potentially emerging as a result of these vulnerabilities.
The ongoing investigation highlights significant risks associated with hardware wallet security and underscores the importance of prompt firmware updates. Continued monitoring by crypto exchanges and cybersecurity teams remains crucial to mitigating potential further losses.
Written by Daniel Brooks
Security Desk