Key Point
Galaxy Research estimated that the Coldcard exploit caused $100 million in losses across three confirmed attack waves and identified a suspected fourth wave that could bring total losses to about $130 million in Bitcoin. Galaxy Digital head of research Alex Thorn said victim reports helped label new attackers that would have gone undiscovered. Thorn said one report of less than 1 BTC stolen led to a newly identified attack with 12 BTC siphoned from 126 addresses. Dragonfly managing partner Haseeb Qureshi said about $2 of AI hardening could have prevented the exploit. Tokenomist data lead Tatsapat Saerejittima said AI discovery claims came after public disclosure and lacked a blind test, documented methodology, and false-positive assessment.
Why it matters: Wallet-security failures may weaken trust in self-custody tools and could push users to reassess storage risk.
Market Sentiment
Bearish, Stress-on, Event-driven, Fear.
Reason: The $100 million loss estimate across three confirmed Coldcard attack waves points to active self-custody risk.
Similar Past Cases
In 2023, Atomic Wallet users lost more than $35 million in a self-custody wallet hack, and the case showed that wallet-layer compromise can create losses without a centralized exchange failure. (Fortune) The mismatch is that Atomic Wallet was a software wallet case, while Coldcard is framed around a hardware wallet vulnerability and private-key setup.
Ripple Effect
A wallet vulnerability can spread through the confidence channel if users question key-generation safety across self-custody tools. If new victim reports keep identifying additional attack waves, then wallet users may shift toward audited setups or custody alternatives. This spillover would likely remain security-led unless losses begin to affect broader liquidity behavior.
Opportunities & Risks
Opportunities: If Galaxy Research confirms that losses remain contained to identified waves, then verified wallet-hardening updates can become a potential confidence signal.
Risks: If victim reports keep expanding the attacker set or loss estimate, then reducing reliance on affected wallet setups limits exposure to key-generation risk.

