Galaxy Flags More Than 15 Distinct Attackers in Ongoing Coldcard Exploit Following New Reports

Galaxy identifies 15+ attackers in the Coldcard exploit as losses may reach $130M and debate grows over cheap AI testing and weak entropy.
Table of Contents

TL;DR

  • Galaxy identified at least 15 attackers after new victim reports exposed previously hidden Coldcard thefts, including 12 BTC removed from 126 addresses.
  • Confirmed losses reached about $100 million across three waves, while a suspected fourth attack could lift the total near $130 million in Bitcoin.
  • Researchers disputed whether cheap AI testing could have prevented the flaw, but agreed that reduced 40-bit entropy made affected wallet seeds easier to attack independently.

Galaxy Digital says at least 15 distinct attackers exploited the Coldcard vulnerability, based on new victim reports after the incident became public. Alex Thorn explained that individual disclosures helped analysts label attackers that otherwise would have remained hidden because the exploit differed from a centralized exchange breach. Fresh reports are revealing a fragmented campaign rather than one coordinated theft operation. In one case, a victim reporting less than 1 BTC stolen enabled researchers to identify an attack that removed 12 BTC from 126 addresses, showing how a small complaint can expose a much wider pattern.

New Reports Expand the Loss Estimate and AI Debate

Galaxy now estimates confirmed losses near $100 million across three attack waves and has identified a suspected fourth wave that could raise the total to approximately $130 million in Bitcoin. The expanding loss estimate suggests the exploit is still being reconstructed rather than fully contained or understood. Unlike a single exchange hack with one visible breach point, compromised wallet seeds can be exploited independently by different actors, making attribution, victim counting and total-loss calculations unusually difficult. The growing attacker count has also reopened questions about whether self-custody protects users when hardware-generated secrets themselves become predictable.

Galaxy identified at least 15 attackers after new victim reports exposed previously hidden Coldcard thefts

The technical discussion has shifted toward how cheaply artificial intelligence might rediscover the firmware flaw. Dragonfly managing partner Haseeb Qureshi argued that roughly $2 of AI hardening could have prevented the incident, citing tests in which models reportedly reproduced the vulnerability within minutes. The AI claim remains provocative but contested because the flaw was already public when several demonstrations occurred. One researcher warned that those tests lacked blind conditions, documented methods and false-positive analysis, while another open-source model reportedly found the issue in 20 minutes without web access, intensifying debate over realistic early pre-disclosure detection.

Castle Labs said the bug reduced Coldcard private-key entropy to about 40 bits, far below the 128 bits associated with a standard 12-word seed. That collapse made brute-force discovery easier and may explain why multiple attackers could participate. The incident exposes a testing failure where a hardware wallet’s security promise depended on entropy that firmware quietly weakened. As AI lowers the cost of code review for both defenders and criminals, the unresolved challenge is whether wallet manufacturers can harden releases before automated tools transform obscure implementation mistakes into scalable theft opportunities across dormant Bitcoin addresses.

RELATED POSTS

Ads

Follow us on Social Networks

Crypto Tutorials

Crypto Reviews