EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

At least 15 attackers exploit Coldcard vulnerability: Galaxy Digital report

2026-08-05 00:53:03
Bookmark

Galaxy Digital Research Director: New victim reports target more attackers, Coldcard vulnerability impact may exceed expectations

Galaxy Digital Research Director said that new victim reports related to the Coldcard vulnerability have helped identify more attackers and pointed out that the impact of the incident may be wider than previously estimated. According to Galaxy Research, the total loss caused by the Coldcard vulnerability has increased to approximately $100 million, involving three confirmed "attack waves", and a fourth wave of attacks may further increase the amount to approximately $130 million (in Bitcoin).

Core Points

Galaxy Digital (Alex Thorn) said that based on newly received victim reports, at least 15 attackers have exploited the Coldcard vulnerability. The damage caused by the three confirmed waves of attacks is estimated to be approximately US$100 million, while a suspected fourth wave of attacks could bring the total damage to approximately US$130 million. Dragonfly's Haseeb Qureshi suggested that "$2 worth of AI hardening" might prevent the exploit, triggering discussions about AI's role in vulnerability discovery. Tokenomist's Tatsapat Saerejittima warned that claims on social media about AI quickly discovering vulnerabilities lack documented blind test verification. Francesco, co-founder of Castle Labs, pointed out that the creation settings of the wallet's private key may be potentially related to the exploitability of the vulnerability.

Victim report reshapes the attacker

In a platform X post posted Tuesday, Galaxy Digital research director Alex Thorn said Galaxy has received more victim reports since the incident-reports that have helped the company identify attacker activity that might otherwise have been ignored. Thorn emphasized that this is not a typical centralized exchange-style attack, and its vulnerability exploitation mechanism is different, so that new attack patterns emerge after victims report details. He also cited as an example: "Just because one victim reported less than 1 bitcoin stolen, we discovered a new attack that stole 12 bitcoins from 126 addresses."

Loss estimates climb, confirming that wave expansion

The wider impact of the wave expansion is reflected in Galaxy Research's data. Estimates of losses related to the Coldcard vulnerability have increased to approximately $100 million, covering three confirmed attacks. Galaxy Research also flagged a suspected fourth wave attack. If this wave is confirmed, the total loss could reach approximately US$130 million (in Bitcoin). The incident has renewed security questions among cold storage users: Although "offline" storage is generally considered more secure than hot wallets, the Coldcard incident shows that even if devices are designed to minimize network exposure, vulnerabilities in wallet firmware or key generation logic can still be exploited.

The AI Hardening War: Speed and Verificability

As the incident simmered, discussions intensified about whether AI could speed up vulnerability discovery and whether defensive "hardening" measures could stop the attack. Haseeb Qureshi, managing partner of Dragonfly, believes that about "$2 worth of AI hardening" can prevent Coldcard attacks. He cited social media accounts that some AI models can quickly rediscover underlying vulnerabilities-one claim that Claude reproduced the problem in eight minutes. Qureshi added that results could be affected by web searches. He also mentioned that the open source AI model GLM 5.2 rediscovered the attack method within 20 minutes when network access was turned off. However, claims that AI quickly spotted vulnerabilities were countered by analysts, who stressed methodological rigor. Tatsapat Saerejittima, head of Tokenomist data, said it was unlikely that AI models would discover the vulnerability independently before it became public. "The claim that AI found the vulnerability in 2 minutes came from an anonymous Reddit user who scanned the code after the vulnerability became public. No blind testing was conducted, no recording methodology, and no assessment of the false alarm rate of the model."

Private key settings may affect exploit

Another technical clue involves how Coldcard constructs the entropy of the private key. Francesco, co-founder of cryptocurrency research firm Castle Labs, said that while AI can reduce the time and cost of discovering cryptocurrency vulnerabilities, the private key setting of the wallet may increase the exploitability of the vulnerability. Francesco said the private key used by Coldcard has an entropy of 40 bits-lower than the level typically used by other wallets. He contrasts this with standard practice: a seed of 12 words corresponds to 128 bits of entropy. He attributed the difference to a firmware vulnerability and said that under typical key entropy assumptions, conditions for vulnerability exploitation may be more favorable than the actual situation. Francesco also pointed out that as AI models increase their capabilities and are more deeply integrated into cybersecurity and attack tools, the overall cost of vulnerability discovery may continue to decline.

What should be followed by investors and users

Given that Galaxy Research has pointed to the possibility of a fourth wave of attacks and analysts are debating the speed at which vulnerabilities are discovered and patched, the focus should shift to whether more victims have confirmed suspected fourth wave attacks and how cold wallet providers will respond-particularly firmware-level assumptions in key generation, and any hardening measures that may reduce the risk of reuse.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP