At least 15 attackers exploited Coldcard vulnerability: Galaxy
Reported by Cointelegraph · AI-assisted summary by ChikoCorp AI News Desk

AI-generated summary based on the linked source; not independently verified. This is not investment advice. Verify market-moving details at the original publisher before acting. See our editorial policy, AI content policy, and financial disclaimer.
Summary
Galaxy Digital’s head of research, Alex Thorn, reported that at least 15 attackers exploited a vulnerability in Coldcard wallets, based on new victim reports received after the incident. The exploit has resulted in estimated losses reaching $100 million in Bitcoin across three confirmed waves, with a suspected fourth wave potentially raising losses to $130 million. The vulnerability was linked to a firmware bug reducing the private key entropy level in Coldcard wallets.
Why it matters
The incident raises concerns about the security of cold storage wallets and whether users can be safer by self-custodying their Bitcoin. It also highlights the increasing role of AI in discovering cryptocurrency vulnerabilities. The exploit and its scale have sparked debate on cold wallet security in the broader crypto community.
Key context
Coldcard wallets had a firmware bug that lowered the private key entropy to 40 bits, much less than the standard 128 bits used by other wallets, making it easier to exploit. AI models reportedly rediscovered the vulnerability quickly after it became public, but some experts disputed claims that AI discovered it independently before public disclosure. The incident involved multiple attack waves and numerous victim reports, revealing a broader scope of attackers than initially known.
Key numbers and entities
Alex Thorn (Galaxy Digital’s head of research), Dragonfly managing partner Haseeb Qureshi, crypto analytics platform Tokenomist’s Tatsapat Saerejittima, and Castle Labs’ co-founder Francesco are key figures mentioned. Estimated losses from the exploit are about $100 million, potentially rising to $130 million with an additional wave. The private key entropy in Coldcard wallets was only 40 bits compared to the 128 bits industry standard.
What remains unclear
The source does not provide detailed technical specifics of the exploit or confirm whether AI could have discovered the vulnerability independently before public disclosure. There is uncertainty around the full extent of attacker identities beyond the 15 reported and whether additional waves of attacks will occur. The true scope of losses and the timeline for addressing the vulnerability remain partly open.