A vulnerability in Coldcard hardware wallets has resulted in the theft of 1,367 Bitcoin, valued at approximately $88.6 million. The ongoing exploit has hit 4,585 distinct addresses across three waves of attacks.
Galaxy Research confirmed the observed losses. Analyst Alex Thorn said the sweeps are deliberate and likely orchestrated by advanced automated systems.
The exploit originates from a firmware update released in March 2021. The flaw exposes seed phrases of single-signature Coldcard wallets created after that update. Galaxy Research warns that every single-signature Coldcard address established post-March 2021 will eventually be drained.
The continuous losses have triggered a shift in user behavior. Many affected users are moving their Bitcoin from self-custodied hardware wallets back to centralized exchanges—a reversal of the "not your keys, not your coins" ethos that has long defined self-custody advocacy.
On-chain data confirms movement of the stolen 1,367 BTC to various addresses, indicating an organized exfiltration strategy.
Bitcoin currently trades at $63,236.
