Galaxy Research reported that at least 1,719 Bitcoins, about US$ 111 million, were stolen in a flaw in Coldcard wallets, with total losses estimated at more than US$ 130 million.
The firm said there are still coins under review and that losses likely exceed US$ 130 million. If suspected cases are confirmed, the total could surpass 2,300 Bitcoins.
How the attack occurred
The vulnerability affected Coldcard wallets with firmware released after March 17, 2021. The flaw compromised the security or generation of the seed, the wallet's master key. With the seed recreated, attackers accessed funds without physically compromising the device.
Investigators identified more than 25 attack patterns in three waves, suggesting the action of multiple groups. No theft was recorded in wallets created before that date.
Impact of the exploit
The attack began on July 30, when an attacker drained approximately 594 BTC, equivalent to US$ 38 million, from 500 wallets in a 15- to 25-minute window.
More than 250 victims reported losses, but the number of affected addresses may be higher, since a single victim may have used multiple wallets. Galaxy Research stated that not all Coldcard wallets were exposed, but the Mk3, Mk4, Mk5, and Q models, with firmware after March 17, 2021, were vulnerable. The Bitcoin mainnet was not affected.



