Coldcard Hackers Drain Over $130M in Coordinated Attacks
A coordinated effort by at least 15 attackers has drained over $132 million in Bitcoin from wallets generated using vulnerable Coldcard firmware, according to research firm Galaxy Research. The total amount stolen may reach as high as 2,055 BTC after a suspected fourth wave of attacks.
The researchers have identified three major waves and 14 smaller incidents that removed approximately 1,596 BTC from around 7,300 addresses. However, the fragmented activity makes attribution difficult due to different consolidation addresses, transaction structures, and spending patterns used by each attacker.
Coldcard developer James O'Beirne had raised concerns about the random-number generation in the May 2025 firmware audit, which was dismissed by Coinkite at the time. The company has since released fixed firmware versions for affected models, including Mk2, Mk3, Mk4, and Q.
The disclosure of the vulnerability led to a surge in Bitcoin activity, with daily active addresses reaching a 2024 high of nearly one million on July 31. Affected users are advised to install fixed firmware, generate a new seed, verify receiving addresses, and migrate their balances to avoid further exposure.