The Coldcard wallet breach is now a sustained campaign. Hackers have drained more than $114 million in Bitcoin across four waves of attacks, with the latest round beginning Sunday evening, according to Galaxy Research’s Alex Thorn.
Thorn posted around 7:50 p.m. New York time that 388.9 BTC, worth over $29 million, had moved in new transactions highly likely tied to the theft. That’s wave four. The first strike hit Thursday, when attackers walked away with more than $35 million.
A Pattern, Not a One-Off
Four waves means this isn’t a single compromised seed phrase or a targeted attack on one high-net-worth user. It’s either a supply-chain compromise, a firmware vulnerability being exploited at scale, or a coordinated breach of multiple users through a shared attack vector. Coldcard’s reputation rests on air-gapped security and open-source firmware, a breach at this scale raises questions about what, exactly, was compromised.
The timing between waves suggests the attacker is working methodically, possibly waiting for fee conditions to improve or moving funds in batches to avoid mempool congestion. That’s not the behavior of a panicked opportunist. It’s patient, deliberate, and ongoing.
No Official Word, Growing Exposure
There’s been no public statement from Coinkite, Coldcard’s manufacturer, clarifying the attack vector or advising users on mitigation. That silence is its own problem. Every hour without guidance leaves remaining users uncertain whether their funds are at risk, whether rotating keys is sufficient, or whether the hardware itself is the vulnerability.
Galaxy’s Thorn is tracking the movements publicly, but he’s not offering a theory on how the wallets were breached. The industry is left to speculate: was it a malicious firmware update, a compromised supply chain during manufacturing, or a previously unknown exploit in the device’s signing process?
The sum is climbing. Four waves in five days, $114 million and counting. If this continues, it will rank among the largest hardware wallet breaches on record. And unless Coinkite surfaces with a clear explanation and a patch, every Coldcard user is left wondering if they’re next.
