Summary
A firmware flaw in a March 2021 Coldcard update has enabled attackers to drain approximately 1,367 BTC (~$88.6M) from 4,585 addresses, with Galaxy Research warning the attack remains active and urging immediate fund migration.
Key Takeaways
Key Takeaways
- The root cause is a March 2021 Coldcard firmware flaw that reduced entropy in seed phrase generation, making private keys for single-signature wallets predictable and systematically exploitable.
- Galaxy Research warns every single-signature wallet created with the flawed firmware remains at risk; users should migrate funds to wallets generated with verified software immediately.
- The exploit triggered the highest daily Bitcoin transaction volume under 1 BTC since November 2022, reflecting a temporary shift away from self-custody toward centralized exchanges among smaller holders.
- At least one victim, Jonathan Goodman, lost 18.25 BTC despite following recommended offline storage practices, demonstrating that physical security measures cannot compensate for cryptographic key generation vulnerabilities.
A large-scale security exploit targeting Coldcard hardware wallets has resulted in the theft of nearly 1,367 Bitcoin, worth approximately $88.6 million, according to researchers at Galaxy Research, who say the attack remains active and could impact additional users.
The latest findings indicate that attackers have already drained funds from 4,585 Bitcoin addresses, with a third wave of thefts pushing total observed losses close to the $90 million mark.
Researchers are urging anyone using potentially affected Coldcard-generated wallets to transfer their assets immediately.
Third Wave Pushes Losses Higher
Galaxy Research reported that an additional 207.73 BTC was stolen during the latest wave of attacks, bringing total estimated losses to approximately 1,367 BTC.
According to Alex Thorn, Galaxy Digital's Head of Firmwide Research, investigators continue to identify both victim and attacker addresses as the exploit unfolds.
"The attack is ongoing," Thorn said in a post on X, advising users to move funds from vulnerable Coldcard-generated addresses without delay.
Galaxy said it has shared hundreds of suspected attacker wallet addresses with law enforcement agencies, compliance providers, and cybersecurity investigators to support ongoing efforts to trace the stolen assets.
Firmware Flaw Linked to Wallet Seed Generation
The exploit has been linked to a flaw introduced in a March 2021 Coldcard firmware update, which reportedly weakened the randomness used during seed phrase generation.
According to researchers, the issue affected the creation of private keys for certain single-signature wallets, making them significantly easier for attackers to predict than intended.
Galaxy believes the thefts were highly automated and coordinated, with Thorn suggesting the attackers may have used advanced automation tools to systematically identify and empty vulnerable wallets.
He also warned that every affected single-signature wallet generated using the flawed firmware could eventually be compromised if funds remain in those addresses.
Long-Term Bitcoin Holders Among the Victims
Researchers noted that many of the stolen Bitcoin had remained untouched for years before being drained.
Galaxy estimates the compromised funds had been dormant for an average of 3.18 years, indicating that many victims were long-term Bitcoin holders who believed their assets were securely stored offline.
At the time of publication, investigators said the stolen funds remained in attacker-controlled wallets and had not yet been moved further.
Self-Custody Confidence Shaken
The exploit has prompted an unusual response across the Bitcoin community, with some affected users temporarily abandoning self-custody in favor of centralized exchanges or newly generated wallets.
On-chain data shared by CryptoQuant Head of Research Julio Moreno showed that Bitcoin transfers below 1 BTC surged on Friday, with approximately 39,600 BTC moved in a single day.
The figure represents the highest daily volume for transactions under one Bitcoin since November 2022, shortly after the collapse of cryptocurrency exchange FTX, suggesting a wave of smaller holders relocating their assets following news of the exploit.
The migration marks a rare reversal of Bitcoin's long-standing "not your keys, not your coins" philosophy, as security concerns temporarily outweighed the preference for self-custody.
Victims Say They Followed Best Practices
Among those affected was Canadian entrepreneur and coach Jonathan Goodman, who said 18.25 BTC was stolen from his wallets within minutes despite storing his recovery phrase offline in a safety deposit box.
Goodman wrote that he had followed recommended security practices and is now reporting the incident to both law enforcement authorities and Canadian regulators.
The incident has renewed debate over hardware wallet security and the importance of verifying firmware integrity, while highlighting that even offline storage solutions remain vulnerable if cryptographic key generation is compromised.
With the ongoing investigation, security researchers are advising all users who may have created Coldcard single-signature wallets using the affected firmware to immediately transfer their Bitcoin to newly generated wallets created with verified software.

