Coldcard Bitcoin Theft Tops $100 Million as Galaxy’s Alex Thorn Tracks a Fourth Wave
Alex Thorn, head of research at Galaxy Digital, said on the Bits + Bips podcast that an exploit of Coldcard hardware wallets has drained “well over $100 million” in bitcoin from self-custodied holders, and walked through...
Archive context
Older archive item. Useful for background and entity history, but not a fresh market-moving signal.
Alex Thorn, head of research at Galaxy Digital, said on the Bits + Bips podcast that an exploit of Coldcard hardware wallets has drained “well over $100 million” in bitcoin from self-custodied holders, and walked through the wave-by-wave forensic trail he has been using to track the attackers — including a suspected fourth wave and about 14 additional attacker patterns he said he had not yet reported.
The episode is one of the fullest public accounts yet of who was hit and why. Thorn, who has been tracing the theft onchain, said he had confirmed three waves and a fourth still in the “medium to high confidence” range.
“Well over $100 million”“We’re well over $100 million of self-custodied Bitcoin,” Thorn said on the podcast, adding that even without the fourth wave the losses cleared that mark. “I would place it more in the 1600 BTC range.” He called it “unprecedented as far as I’m aware” for a distributed self-custody hack.
The tally has climbed since the taping. By Thorn’s count, three confirmed waves have taken about 1,367 BTC — near $89 million — from roughly 4,585 addresses. Folding in a suspected fourth sweep he flagged August 3, which moved hundreds more coins through a burst of blocks at about 45 times the normal rate, the total rises to roughly 1,815 BTC, or near $114 million, across some 5,294 addresses.
Fourteen more patternsBeyond the numbered waves, Thorn said on the show he had found still more attackers — “14 other identifiable patterns that we have found that do not appear related to any of those waves, but do have verifiable victims” — that he had not folded into the headline count and planned to detail on X.
A silent firmware flawThe exploit traces to a March 17, 2021 Coldcard firmware update that added the company’s own random number generator but, Thorn said on the podcast, “miswired it” so that key generation would “fail silently” and fall back to a generator with “way too weak entropy” to be secure. Attackers with enough compute could then reproduce the keys and sweep the coins.
“These people did nothing wrong,” Thorn said on the show. “In fact, they did everything right.” He described the victims as long-term holders — the average stolen coin had sat untouched for nearly four years — rather than speculators, and urged anyone holding bitcoin on a single-signature Coldcard address to “move those coins off as soon as possible.”
Coinkite takes “full accountability”Coinkite, the Canadian company that makes Coldcard, has taken public responsibility. Chief executive Rodolfo Novak apologized on X, writing that the company was “heartbroken” and taking “full accountability for the firmware bug,” and Coinkite has shipped a fixed firmware. The company warned, however, that the update does not protect seeds already generated on the flawed software; those funds have to be moved to a wallet created with the fix.
Thorn also pointed to a narrow recovery path. Because some of the theft transactions signal replace-by-fee, a victim who spots their coins still unconfirmed in the mempool may be able to outbid the attacker and move the funds first. He urged victims to file reports with the FBI’s IC3 and their local police, and to keep the compromised device as evidence.
Related Listen: Strategy Sells $216M in Bitcoin. Is Saylor a Buyer or a Seller Now?: Bits + Bips
{"@context":"http:\/\/schema.org\/","@id":"https:\/\/unchainedcrypto.com\/coldcard-bitcoin-theft-tops-100-million-as-galaxys-alex-thorn-tracks-a-fourth-wave\/#arve-youtube-h3z68syty0k","@type":"VideoObject","embedURL":"https:\/\/www.youtube-nocookie.com\/embed\/H3z68SYty0k?feature=oembed&iv_load_policy=3&modestbranding=1&rel=0&autohide=1&playsinline=1&autoplay=0"}
The post Coldcard Bitcoin Theft Tops $100 Million as Galaxy’s Alex Thorn Tracks a Fourth Wave appeared first on Unchained.
Why this matters
Bitcoin is showing up inside the Security Incidents theme, so this story is worth tracking for follow-through rather than treating it as a one-off headline.
Original source
Read on UnchainedRelated market context
Ledger investigates wallet tampering tied to tens of millions in crypto thefts
The investigation highlights the critical need for enhanced security measures and trust in crypto hardware supply chains to preven...
Ledger hack scare nears $90 million as Tether moves to freeze stolen USDT
Suspected Ledger wallet thefts are approaching $90 million as Tether freezes USDT stablecoin linked to the incident, according to...
Tether freezes USDT linked to Ledger user thefts near $90 million
The freeze highlights the need for robust supply chain security and raises concerns about the limitations of centralized control i...
Samsung Wallet Brings USDC to 82M Galaxy Devices With Coinbase, Solana and Sui Support
Key Takeaways: Samsung Wallet will support 82 million U.S. Galaxy to add transfers on USDC. Coinbase will keep USDC in their Coinb...
AI Could Weaken Ethereum Security as Cryptographic Risks Grow, Vitalik Buterin Warns
Buterin urged developers to prepare for potential AI vulnerabilities in both conventional and quantum-resistant cryptography, whil...
Ledger theft-linked funds shift from USDT to USDD to dodge Tether freezes
The shift from USDT to USDD underscores vulnerabilities in stablecoin freeze mechanisms, prompting scrutiny on regulatory and secu...