At least 15 attackers exploited Coldcard vulnerability: Galaxy
Galaxy Digital says at least 15 attackers have exploited the Coldcard vulnerability, based on new victim reports that exposed previously unseen thefts. Alex Thorn said even small reports helped identify additional campaigns, including one case where less than 1 BTC reported led to discovery of 12 BTC stolen from 126 addresses. Estimated losses have risen to about $100 million across three confirmed waves, with a suspected fourth wave that could push losses near $130 million in BTC. The incident renewed debate over cold storage security. Dragonfly’s Haseeb Qureshi argued that relatively little “AI hardening” might have prevented the bug, citing claims that AI models rapidly reproduced the flaw. Others pushed back, saying the tests were not rigorous and were conducted after the vulnerability was already public. Castle Labs’ Francesco said Coldcard’s weak private key entropy — about 40 bits versus the 128 bits of a 12-word seed — likely made exploitation easier, and warned AI is lowering the cost of finding crypto bugs.
