Coldcard Vulnerability Exploit May Be Wider Than Thought
The Coldcard vulnerability incident has revealed more attackers than initially thought, with at least 15 exploiters identified by Galaxy Digital's research team. The team's analysis of newly received victim reports led to this discovery, highlighting that the incident may be broader than earlier estimates suggested.
Estimated losses tied to the Coldcard exploit have increased to about $100 million across three confirmed attack waves, with a possible fourth wave that could push the figure closer to $130 million in Bitcoin. The team's research chief, Alex Thorn, pointed out that this was not a typical centralized-exchange-style compromise, but rather a unique exploit mechanism.
One example of how these additional victims were identified came from a report of less than 1 BTC stolen, which led to the discovery of a new attack with 12 BTC siphoned from 126 addresses. This finding demonstrates that detailed victim reports can significantly aid in identifying and labeling attacker activity that might otherwise have gone unnoticed.
The incident has sparked debate about the role of AI in vulnerability discovery and mitigation. Dragonfly's Haseeb Qureshi argued that '2 of AI hardening' could have prevented the exploit, while Tokenomist's Tatsapat Saerejittima cautioned that social media claims about rapid AI discovery were not based on a documented blind test.
Crypto research company Castle Labs' co-founder, Francesco, pointed to a potential link between Coldcard's private key setup and the vulnerability's exploitability. He suggested that the wallet used a lower level of private key entropy than other wallets, making it more susceptible to exploitation.