Coldcard Hardware Wallet Breach Reaches $115M as Galaxy Research Tracks Over 200 Victims

September 9, 2026 112 views

Galaxy Research reports that losses from the ongoing Coldcard hardware wallet exploit have surpassed $115 million in bitcoin, based on prices at the time of theft. The firm has engaged with more than 200 affected users to provide support and collect intelligence on the attackers.

Firmware Vulnerability Exposed After Years

The security breach stems from a firmware bug in Coinkite's Coldcard Mk3 devices that went undetected for over three years. The vulnerability, present in firmware version 4.0.1 and later releases beginning in March 2021, caused the device's seed generation to revert to a weak software pseudorandom number generator instead of the hardware-based true random number generator.

This critical flaw enabled attackers to predict user seed phrases, compromising the core security feature of the popular Bitcoin storage solution. Coinkite acknowledged in a statement that the bug "silently went unnoticed" and that "its potential impact grew with every release" of subsequent firmware versions.

Multiple Attack Groups Target Long-Term Holders

The exploitation began on July 31, with Galaxy Research identifying at least 15 separate groups independently exploiting the vulnerability. Analysis of stolen funds reveals that 88% of compromised bitcoin had remained untouched for at least one year, with the average affected holding sitting dormant for 3.5 years. This indicates that attackers specifically targeted long-term holders who may have been less likely to monitor their wallets regularly.

Galaxy Research continues to verify the scope of losses and estimates total damages could exceed $130 million. The Canadian hardware wallet manufacturer has urged users to immediately migrate funds and update their firmware.

Workforce Implications

This incident underscores the growing demand for security-focused roles in the cryptocurrency industry. Companies building custody solutions and wallet infrastructure will likely accelerate hiring for security engineers, firmware developers, and penetration testers to prevent similar vulnerabilities. For professionals in blockchain security, this breach reinforces the critical nature of rigorous testing protocols and the need for continuous monitoring of cryptographic implementations across hardware and software systems.