Crypto World
At Least 15 Attackers Used Coldcard Vulnerability: Galaxy Digital
Galaxy Digital’s research chief says new victim reports tied to the Coldcard vulnerability have enabled the identification of additional attackers—highlighting that the incident may be broader than earlier estimates suggested.
According to Galaxy Research, the total losses tied to the Coldcard exploit have increased to about $100 million across three confirmed “attack waves,” with a possible fourth wave that could push the figure closer to $130 million in Bitcoin.
Key takeaways
- Galaxy Digital (Alex Thorn) says at least 15 attackers exploited the Coldcard vulnerability, based on newly received victim reports.
- Estimated losses have risen to roughly $100 million across three confirmed waves, with a suspected fourth wave that could increase totals to about $130 million.
- Dragonfly’s Haseeb Qureshi argues that “$2 of AI hardening” might have prevented the exploit, sparking a debate over AI’s role in vulnerability discovery.
- Tokenomist’s Tatsapat Saerejittima cautions that social media claims about rapid AI discovery were not based on a documented blind test.
- Castle Labs co-founder Francesco points to a potential link between the wallet’s private key setup and the vulnerability’s exploitability.
Victim reports reshape the attacker picture
In a Tuesday X post, Alex Thorn, head of research at Galaxy Digital, said Galaxy had received additional victim reports since the incident—reports that helped the firm label attacker activity that might otherwise have gone unnoticed.
Thorn’s comments emphasize that this was not a typical centralized-exchange-style compromise. Instead, the exploit mechanism differed in a way that made new patterns detectable once victims began reporting details.
He also cited an example: “Due to one single victim’s report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses,” Thorn wrote.
Loss estimates climb as confirmed waves expand
The broader impact is reflected in Galaxy Research’s figures. Loss estimates connected to the Coldcard exploit have grown to about $100 million across three confirmed attack waves.
Galaxy Research has also flagged a suspected fourth wave. If that additional wave is confirmed, the total losses could reach approximately $130 million in Bitcoin.
The incident has reopened ongoing security questions for cold storage users: while “offline” storage is generally considered safer than hot, connected systems, the Coldcard incident underscores that vulnerabilities in wallet firmware or key-generation logic can still be exploited—even when the device is designed to minimize exposure to networks.
AI hardening debate: speed claims vs. testability
As the incident spread, discussion intensified around whether advances in AI could accelerate vulnerability discovery and whether defensive “hardening” could have stopped the exploit. Dragonfly managing partner Haseeb Qureshi argued that roughly “$2 of AI hardening” could have prevented the Coldcard attack.
Qureshi referenced social media reports suggesting that some AI models were able to rediscover the underlying vulnerability quickly—one claim centered on Claude regenerating the issue in eight minutes. Qureshi added that the results may have been influenced by web search.
He also pointed to an example involving the open-source AI model GLM 5.2, stating that it was able to rediscover the attack in 20 minutes with web access turned off.
However, the narrative around rapid AI discovery met pushback from analysts who stress methodological rigor. Tokenomist’s data lead, Tatsapat Saerejittima, told Cointelegraph that it is unlikely AI models would have independently found the vulnerability before it was public.
“The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model’s false-positive rate.”
Where private key setup may have mattered
Another technical thread concerns how Coldcard structured private key entropy. Crypto research company Castle Labs’ co-founder, Francesco, told Cointelegraph that while AI can reduce the time and cost of discovering cryptocurrency vulnerabilities, the wallet’s private key may have contributed to the exploitability.
Francesco said Coldcard used a level of private key entropy of 40 bits—lower than what other wallets typically adopt. He compared this to a standard approach where a 12-word seed corresponds to 128 bits of entropy. He attributed the difference to a firmware bug, suggesting the conditions for exploitation may have been more favorable than they would be under typical key-entropy assumptions.
Francesco also indicated that, as AI models become more capable and more integrated into both cybersecurity and offensive tooling, the broader cost of bug discovery is likely to keep dropping.
What investors and users should watch next
With Galaxy Research pointing to a possible fourth attack wave and analysts debating how quickly vulnerabilities can be rediscovered and mitigated, attention should shift toward whether additional victims corroborate the suspected wave and how cold-wallet vendors respond—particularly around firmware-level assumptions in key generation and any hardening measures that could reduce the chance of repeat exploitation.
You must be logged in to post a comment Login