
Galaxy Digital’s research team says the Coldcard wallet exploit has been used by at least 15 different attackers, based on new victim reports submitted after the incident. In remarks shared this week, Alex Thorn, head of research at Galaxy Digital, suggested that these additional reports helped identify variants that might otherwise have remained hidden.
Thorn also indicated that losses tied to the exploit have risen as investigators mapped multiple waves of activity. Galaxy Research estimates the confirmed thefts total about $100 million across three waves, with an additional suspected fourth wave that could lift the figure to roughly $130 million in Bitcoin.
Key takeaways
- Galaxy Digital reports at least 15 distinct attackers behind the Coldcard exploitation, based on newly received victim accounts.
- Galaxy Research estimates confirmed losses at about $100 million across three attack waves, with a potential fourth wave raising the estimate to ~$130 million.
- Security debate is returning to cold storage practices, particularly how much safety comes from self-custody versus wallet design.
- Industry discussion highlights how emerging AI capabilities could lower the time and cost of vulnerability discovery—though independent validation remains limited.
- Researchers point to wallet entropy and firmware behavior as potential factors that make exploitation easier under certain conditions.
Coldcard thefts widen as investigators compare victim reports
In a Tuesday post on X, Thorn said that new victim reports enabled Galaxy to identify additional attacker activity. He framed the significance of the new reporting as both quantitative and technical: the exploit behavior differed from typical theft patterns seen in hacks against centralized exchanges, making careful attribution and investigation more dependent on detailed victim information.
Thorn wrote that even a relatively small report—less than 1 BTC stolen from a victim—was sufficient to detect a new attack pattern. He noted that this new attack involved roughly 12 BTC siphoned from 126 addresses, underscoring how the same underlying vulnerability could be used in different operational ways.
Earlier coverage of the Coldcard exploitation described multiple “waves” of activity. Galaxy Research’s current figures build on that approach by tracking confirmed incidents and assessing whether activity patterns resemble a further wave of exploitation.
Loss estimates: three confirmed waves, plus a suspected fourth
According to Galaxy Research, the total losses from the Coldcard exploit have grown to approximately $100 million across three confirmed attack waves. Thorn’s research also points to a suspected fourth wave that, if validated, would bring the potential total to about $130 million in Bitcoin.
For users and investors, the practical value of this breakdown is that it turns an incident that initially looked like a one-off event into something closer to an evolving campaign. Waves of theft imply repeated operational access—either through different attacker infrastructure, different timing, or different exploit paths that still converge on the vulnerable behavior.
Debate over “AI hardening” and whether models can rediscover exploits
The renewed attention has also reopened a broader debate: whether AI tools can meaningfully compress the time between disclosure and exploitation, and whether “AI hardening” could have prevented the attack.
Dragonfly managing partner Haseeb Qureshi argued on X that “$2 of AI hardening” could have stopped the Coldcard exploit, citing social media claims that some AI models rediscovered the underlying vulnerability in under 20 minutes. His comments referenced reports that a model named Claude could regenerate the vulnerability in eight minutes, as well as a separate claim that an open-source model (GLM 5.2) could rediscover the exploit in 20 minutes even with web access disabled.
However, Tokenomist data lead Tatsapat Saerejittima told Cointelegraph that it is unlikely AI models would have independently found the vulnerability before it became public. Saerejittima argued that the most prominent “fast rediscovery” claim appears to stem from a pseudonymous user who scanned code after the vulnerability was already known, without a blind test, a documented methodology, or an assessment of false-positive rates.
“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.”
That distinction matters. If “rediscovery” is based on post-disclosure inputs, then the timeframe reflects reuse of known information rather than a model’s ability to autonomously uncover unknown vulnerabilities under real-world conditions. For wallet users, builders, and auditors, the difference affects how confidently security teams can treat AI-assisted testing as a substitute for formal review and threat modeling.
Private key setup and entropy may have made exploitation easier
Another line of analysis focuses less on AI capabilities and more on the cryptographic design and implementation details of the device’s key generation process.
Crypto research company Castle Labs co-founder Francesco said that increasing AI capabilities could reduce the cost and time needed to discover cryptocurrency vulnerabilities. He also suggested that Coldcard’s private key may have played a role in why the exploit worked.
Francesco pointed to a “level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits).” He attributed this discrepancy to a firmware bug, which he said would make exploitation easier because the search space is smaller than it would be under typical seed-based entropy assumptions.
He further stated that he expects the cost of bug discovery to continue decreasing as AI models improve and become more embedded in both cybersecurity workflows and exploitation attempts. Even without relying on any single “AI rediscovery” claim, the underlying idea—that automation can accelerate identification and exploitation—aligns with the broader security trend toward faster vulnerability discovery and weaponization.
In practice, these findings shift attention to what should change next for hardware wallet security: not only whether vulnerabilities are found quickly, but how wallet firmware handles entropy, key generation, and edge cases that could alter the effective security assumptions.
As the industry digests Galaxy’s expanding attribution data and the ongoing discussion of exploit mechanics, readers should watch for whether additional theft activity continues to be classified into further waves—and, just as importantly, what technical mitigations are recommended or adopted to address the entropy or firmware conditions implicated by researchers.
https://www.cryptobreaking.com/at-least-15-attackers-exploited/?utm_source=blogger%20&utm_medium=social_auto&utm_campaign=At%20Least%2015%20Attackers%20Exploited%20Coldcard%20Vulnerability:%20Report%20
Comments
Post a Comment