A third wave of thefts from Coldcard hardware wallets has driven cumulative losses to approximately 1,367 BTC worth $88 million across 4,585 compromised addresses, according to Galaxy Research analysis.
The exploit targets Coldcard devices running vulnerable firmware versions. Attackers drain wallets without triggering typical security protocols. The vulnerability appears to persist across multiple iterations of theft, suggesting either a systemic flaw in Coldcard's security architecture or a window of exploitation that remains open despite prior disclosures.
Coldcard, manufactured by Coinkite, positions itself as an air-gapped hardware wallet designed for Bitcoin self-custody. The device stores private keys offline, theoretically isolating them from network-connected attack vectors. The scale of losses indicates the vulnerability bypasses these core security assumptions.
Galaxy Research's tracking shows the attack pattern continues. Attackers maintain active wallet drainage operations, pulling BTC from addresses faster than victims discover compromises. The third wave escalation suggests limited awareness among affected users or insufficient remediation across the Coldcard user base.
The incident raises questions about firmware update penetration and user response timelines. Hardware wallet compromises typically rely on either physical tampering, supply-chain injection, or exploitable software flaws. The consistent success across thousands of addresses points toward a software vulnerability rather than individual device tampering.
Coldcard users holding significant Bitcoin positions now face pressure to migrate funds to alternative solutions. Other hardware manufacturers including Ledger, Trezor, and Foundation have remained unaffected by this specific exploit, making them potential migration targets for security-conscious holders.
The $88 million aggregate loss represents one of the largest hardware wallet exploitation events on record. The ongoing nature of the third wave suggests the vulnerability remains active. Coldcard users without current firmware patches face continued risk. The incident underscores risks inherent in centralized hardware wallet architectures where a single firmware flaw can compromise thousands of private keys simultaneously.
