Coldcard Bitcoin Theft Tops $100 Million as Galaxy’s Alex Thorn Tracks a Fourth Wave
Alex Thorn, head of research at Galaxy Digital, said on the Bits + Bips podcast that an exploit of Coldcard hardware wallets has drained “well over $100 million” in bitcoin from self-custodied holders, and walked through...
High signal
Published in the last two hours. The story has cross-source confirmation.
Alex Thorn, head of research at Galaxy Digital, said on the Bits + Bips podcast that an exploit of Coldcard hardware wallets has drained “well over $100 million” in bitcoin from self-custodied holders, and walked through the wave-by-wave forensic trail he has been using to track the attackers — including a suspected fourth wave and about 14 additional attacker patterns he said he had not yet reported.
The episode is one of the fullest public accounts yet of who was hit and why. Thorn, who has been tracing the theft onchain, said he had confirmed three waves and a fourth still in the “medium to high confidence” range.
“Well over $100 million”“We’re well over $100 million of self-custodied Bitcoin,” Thorn said on the podcast, adding that even without the fourth wave the losses cleared that mark. “I would place it more in the 1600 BTC range.” He called it “unprecedented as far as I’m aware” for a distributed self-custody hack.
The tally has climbed since the taping. By Thorn’s count, three confirmed waves have taken about 1,367 BTC — near $89 million — from roughly 4,585 addresses. Folding in a suspected fourth sweep he flagged August 3, which moved hundreds more coins through a burst of blocks at about 45 times the normal rate, the total rises to roughly 1,815 BTC, or near $114 million, across some 5,294 addresses.
Fourteen more patternsBeyond the numbered waves, Thorn said on the show he had found still more attackers — “14 other identifiable patterns that we have found that do not appear related to any of those waves, but do have verifiable victims” — that he had not folded into the headline count and planned to detail on X.
A silent firmware flawThe exploit traces to a March 17, 2021 Coldcard firmware update that added the company’s own random number generator but, Thorn said on the podcast, “miswired it” so that key generation would “fail silently” and fall back to a generator with “way too weak entropy” to be secure. Attackers with enough compute could then reproduce the keys and sweep the coins.
“These people did nothing wrong,” Thorn said on the show. “In fact, they did everything right.” He described the victims as long-term holders — the average stolen coin had sat untouched for nearly four years — rather than speculators, and urged anyone holding bitcoin on a single-signature Coldcard address to “move those coins off as soon as possible.”
Coinkite takes “full accountability”Coinkite, the Canadian company that makes Coldcard, has taken public responsibility. Chief executive Rodolfo Novak apologized on X, writing that the company was “heartbroken” and taking “full accountability for the firmware bug,” and Coinkite has shipped a fixed firmware. The company warned, however, that the update does not protect seeds already generated on the flawed software; those funds have to be moved to a wallet created with the fix.
Thorn also pointed to a narrow recovery path. Because some of the theft transactions signal replace-by-fee, a victim who spots their coins still unconfirmed in the mempool may be able to outbid the attacker and move the funds first. He urged victims to file reports with the FBI’s IC3 and their local police, and to keep the compromised device as evidence.
Related Listen: Strategy Sells $216M in Bitcoin. Is Saylor a Buyer or a Seller Now?: Bits + Bips
{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/coldcard-bitcoin-theft-tops-100-million-as-galaxys-alex-thorn-tracks-a-fourth-wave\/#arve-youtube-h3z68syty0k","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/H3z68SYty0k?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}
The post Coldcard Bitcoin Theft Tops $100 Million as Galaxy’s Alex Thorn Tracks a Fourth Wave appeared first on Unchained.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on UnchainedSame story, other sources
Cross-source coverage
2 sources
Galaxy Research Puts Confirmed Coldcard Losses Above $100 Million as a Suspected Fourth Wave Nears $130 Million
Confirmed losses from the Coldcard hardware wallet exploit have crossed $100 million, with Gala...
Bitcoin losses from Coldcard hack could swell to $130 million, Galaxy Research says
Galaxy said on X that it suspects the losses to be greater once the yet-unconfirmed fourth wave...
Related market context
Coldcard’s $130 million crisis is pushing Bitcoin back into Wall Street’s hands
The Coldcard hardware wallet exploit has resulted in the theft of at least 1,596 BTC from about 7,300 addresses as users continue...
After the Coldcard Hack, Can Victims Sue? Crypto’s Own Lawyers See an Uphill Battle
The theft of more than $100 million in bitcoin from Coldcard hardware wallets has already reopened the debate over self-custody. O...
FBI Agent Accused of $1 Million Crypto Theft From ‘Adversarial Nation’
Bitcoin Magazine FBI Agent Accused of $1 Million Crypto Theft From ‘Adversarial Nation’ A Federal Bureau of Investigation agent al...
COLDCARD Hack Explodes to 2,055 BTC Losses, Hitting 7,700+ Wallets in $130M Bitcoin Blow
Key Takeaways: Estimated damages from the COLDCARD hack have also risen to 2,055 BTC, or approximately $130 million. Over 7,700 Bi...
Denver Bitcoin shoots his ColdCard Q to protest firmware vulnerability
The incident highlights the critical need for robust firmware security and user education in maintaining trust in hardware wallet...
Coldcard Bitcoin exploit explained: How a firmware bug turned entropy into a ticking time bomb
The Coldcard exploit underscores the critical need for rigorous security audits in crypto hardware, reigniting debates on self-cus...