Coldcard hardware wallet users face confirmed theft totaling over $100 million across three separate attack waves, according to Galaxy Research. The security firm identified coordinated breaches targeting the popular Bitcoin custody device, with 90% of stolen BTC remaining stationary on-chain, likely held by attackers in preparation for delayed movement to obscure fund trails.

Galaxy researchers detected evidence of a suspected fourth wave under investigation that could push cumulative losses to $130 million. The pattern suggests organized attackers are stockpiling rather than immediately converting stolen holdings, a tactical delay that complicates law enforcement tracking while allowing time for market liquidity preparation or privacy mixing.

Coldcard hardware wallets function as offline storage devices designed to isolate private keys from internet-connected systems. The breach scale indicates either a sophisticated supply chain compromise, a critical firmware vulnerability, or successful social engineering targeting multiple users during setup or recovery phases. The stationary Bitcoin holdings suggest attackers either lack immediate exit liquidity, fear drawing regulatory attention through rapid exchanges, or are coordinating a timed liquidation strategy.

The immobility of 90% of stolen funds presents a unique window for recovery efforts and investigative work. On-chain forensics firms can monitor addresses continuously, and law enforcement may pressure exchanges to flag incoming transactions from identified theft wallets. However, the attackers' apparent patience signals potential access to off-ramp routes outside traditional exchanges or intention to hold long-term.

Coldcard's parent company Coinkite has not yet confirmed full scope details in available reports. Hardware wallet security remains critical infrastructure for institutional and retail Bitcoin holders. This incident underscores recurring tensions between offline storage reliability and supply chain vulnerabilities. Users storing significant holdings face pressure to verify device authenticity and firmware integrity, while the industry confronts questions about whether current verification mechanisms sufficiently protect against determined attackers operating at scale.

The fourth wave investigation suggests the attack remains active rather than concluded, creating ongoing risk for Coldcard users who have not yet validated their device security posture.