Coldcard Vulnerability Exploited by at Least 15 Attackers, Total Losses Reach $100M
The recent Coldcard vulnerability has led to at least 15 different attackers exploiting it, according to Galaxy Digital's head of research, Alex Thorn. Since the incident, new victim reports have been received, helping the company identify additional attackers that would have otherwise gone undetected.
The estimated losses from the Coldcard exploit have grown to $100 million across three confirmed attack waves, with a suspected fourth wave bringing total losses to around $130 million in Bitcoin (BTC).
Roughly $2 worth of AI hardening could have prevented the exploit, claimed Dragonfly managing partner Haseeb Qureshi. However, crypto analytics platform Tokenomist's data lead, Tatsapat Saerejittima, disputed this claim, stating that a pseudonymous Reddit user who scanned the code after the vulnerability became public was behind the alleged discovery.
Crypto research company Castle Labs' co-founder, Francesco, attributed the ease of exploiting the Coldcard vulnerability to its private key setup. The firm used a level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), making it easier for attackers.
Francesco also expects the cost of bug discovery to continue decreasing as AI models gain more capabilities and become more prominent in both cybersecurity and exploits.