BNB $593.42 +0.36%
XRP $1.08 -0.11%
ETH $1,872.64 +0.13%
BTC $64,132.36 +0.44%
BNB $593.42 +0.36%
XRP $1.08 -0.11%
ETH $1,872.64 +0.13%
BTC $64,132.36 +0.44%
BREAKING
Digital Wallet

Coldcard’s $100M Hack Exposes 40-Bit Entropy Flaw Across 126 Addresses

Coldcard's $100M Hack Exposes 40-Bit Entropy Flaw Across 126 Addresses
Coldcard's $100M Hack Exposes 40-Bit Entropy Flaw Across 126 Addresses

Community Trust ScoreVerified

97%
Real
Verified30 votes
Updated 5 hours ago

At least 15 attackers tore through Coldcard wallets and walked away with roughly $100 million. Three confirmed waves of exploitation. Possibly a fourth on the way.

Galaxy Digital’s research team put the number together, and it’s ugly. Alex Thorn, head of research at Galaxy Digital, said new victim reports kept coming in, each one illuminating fresh attack activity. One report — a theft of less than a single Bitcoin — ended up cracking open something much bigger. Investigators traced that thread back to an operation that drained 12 BTC spread across 126 addresses. That’s not a one-off. That’s a coordinated, methodical sweep of wallets most users probably assumed were sitting safely offline, untouchable.

Cold wallets are supposed to be the gold standard. The whole pitch is that keeping your keys off the internet protects you. The Coldcard incident kind of blows that assumption up.

Advertisement

The Firmware Bug Behind the Breach

Francesco, co-founder of Castle Labs, pointed to the root cause: a firmware bug that dropped private key entropy down to just 40 bits. Standard wallets run at 128 bits. That gap is enormous. Lower entropy means weaker encryption, and weaker encryption means attackers don’t need to be especially sophisticated — they just need time and compute. With 40-bit entropy, that bar drops dramatically. Francesco said the bug basically handed attackers a shortcut, letting them work through possible key combinations at a pace that would’ve been impossible against a properly secured wallet.

It’s a reminder that cold storage security isn’t just about keeping a device unplugged. The firmware running underneath matters just as much. A single overlooked bug in the code can quietly hollow out protections that users trust with their entire holdings.

AI Found the Flaw in Under 20 Minutes

Here’s where it gets uncomfortable for the industry. Haseeb Qureshi, managing partner at Dragonfly, said a $2 investment in AI hardening probably could’ve stopped all of this. Two dollars. Reports from social media backed him up in a rough way — some AI models, including Claude, apparently spotted the vulnerability in under eight minutes. The open-source model GLM 5.2 found it in 20 minutes, and it did so without internet access.

That’s fast. Faster than most security audits. Faster than most bug bounty hunters would’ve moved.

Not everyone’s convinced, though. Tatsapat Saerejittima from Tokenomist pushed back, saying it’s hard to believe AI models would’ve independently caught this flaw before it went public. Fair point. There’s a difference between running a known vulnerability through a model after the fact and expecting that same model to proactively surface an obscure firmware bug during development. Those are very different tasks.

But Francesco’s read is more forward-looking. He thinks AI models are already cutting the time and cost it takes to find crypto vulnerabilities, and that trajectory isn’t slowing down. As these tools get sharper, wallet developers who don’t build AI-assisted auditing into their process are probably going to fall behind.

A Fourth Wave May Push Losses to $130 Million

Galaxy Research isn’t done counting. The team suspects a fourth wave of attacks could push total losses from $100 million closer to $130 million. No confirmed timeline on that. No details yet on how many additional addresses might be affected. The investigation is still moving.

What’s clear is that the three confirmed waves weren’t random. Fifteen attackers, multiple rounds, 126 addresses already confirmed drained. The operation had structure. And if the fourth wave materializes, it’ll cement this as one of the more damaging cold wallet exploits on record.

The broader crypto community has been loud about this. Cold storage has long been treated as the safe answer to exchange hacks and custodial failures — the lesson drilled into anyone who lost funds during exchange collapses. But the Coldcard situation shows that cold wallets aren’t immune. They’re just exposed to different risks. Firmware bugs, entropy weaknesses, supply chain issues — these are real attack surfaces, and they don’t get patched the way a hot wallet’s backend might.

Wallet developers are probably going to face harder questions now. Users want to know what entropy levels their keys are generated at. They want firmware audits made public. They want some assurance that the device sitting in their drawer isn’t quietly vulnerable to an attack that costs $2 in AI compute to execute.

Francesco’s point about AI reducing the cost of finding vulnerabilities cuts both ways. It’s good news if wallet developers use it proactively. It’s bad news if attackers get there first.

Galaxy Digital’s team is still tracking the situation. The potential fourth attack wave remains a live concern.

Frequently Asked Questions

How much was stolen in the Coldcard wallet exploit?

At least $100 million was lost across three confirmed attack waves, with Galaxy Research saying a fourth wave could push total losses to around $130 million.

What caused the Coldcard vulnerability?

A firmware bug reduced private key entropy to 40 bits, far below the 128-bit standard, making wallets significantly easier to compromise, according to Francesco, co-founder of Castle Labs.

Community Trust IndexHigh Confidence
97%
Real
Real97%3%Fake
30 community signals

Sakamoto Nashi

Nashi Sakamoto is a dedicated crypto journalist from the Virgin Islands who brings expert analysis on Bitcoin, Ethereum, DeFi protocols, and the broader digital asset ecosystem to The Currency Analytics.

Advertisement

Related Stories