π° Key Summary
The Coldcard hardware wallet vulnerability incident continues to grow. Galaxy Digital’s head of research Alex Thorn says victim reports keep coming in, with at least 15 different attackers now confirmed to have exploited the same flaw. One case stands out: a single victim reported losing less than 1 BTC, but digging into it uncovered a whole new wave of attacks β hackers stole 12 BTC total across 126 addresses. It shows how this kind of decentralized, non-exchange-style attack is nearly impossible to spot from any one incident alone; the full picture only comes together as more victims report in. Galaxy Research estimates total losses across three confirmed waves of attacks have climbed to around $100 million, and they’ve also spotted signs of a possible fourth wave β if confirmed, total losses (in BTC terms) could approach $130 million.
As for the root cause, Francesco, co-founder of Castle Labs, points to a firmware bug in Coldcard that left private key entropy at just 40 bits β way below the industry standard of 128 bits used by wallets with 12-word seed phrases. That gap made the keys dramatically easier to crack.
The incident has also sparked debate over whether AI sped up the discovery of the vulnerability. Dragonfly managing partner Haseeb Qureshi says word in the community is that Claude reproduced the exploit in just 8 minutes, and the open-source model GLM 5.2 did it in 20 minutes with web search turned off β suggesting a mere “$2 worth of AI-assisted testing” could have caught and prevented this whole mess earlier. But Tatsapat Saerejittima, head of data at crypto analytics platform Tokenomist, pushed back, saying the claim about AI “finding the bug in 2 minutes” actually came from an anonymous Reddit user scanning the code after the vulnerability was already public β not a blind test, and with no documented methodology or false-positive rate. In other words, the evidence is thin. The whole episode has reignited debate over cold wallet security and the risks of self-custody for Bitcoin holders.
π¬ JudyAI Lab Take
Multiple attackers exploiting the same Coldcard hardware wallet vulnerability, with cumulative losses now nearing $100 million β this is forcing a real re-examination of the trust assumptions behind cold wallets.
What matters here isn’t the size of any single attack β it’s what this incident reveals about two structural problems in hardware wallet security. First, a firmware bug cut private key entropy down to 40 bits, far below the industry’s 128-bit standard, meaning the security was compromised at the design level, not from user error. Second, the attacks were spread across 126 addresses and carried out by 15+ separate attackers β a decentralized pattern that makes it nearly impossible for any single victim to see the full scope, forcing the picture to be pieced together after the fact. The lesson for AI builders: security testing can’t just verify that a feature works β it needs to verify that the underlying assumptions (entropy, randomness, etc.) actually hold up under extreme conditions. As for whether AI accelerated the vulnerability discovery, both sides of that debate are still missing rigorous methodology, so it’s worth watching rather than jumping to conclusions.
If your product also relies on cryptographic security, it’s worth taking another look at where your key generation entropy comes from and how it stacks up against industry standards.
π Original Article Info
- Published: 2026-08-04T14:38
- Source: https://cointelegraph.com/news/15-attackers-exploited-coldcard-vulnerability-galaxy?utm_source=rss_feed&utm_medium=rss_tag_ai&utm_campaign=rss_partner_inbound