Digital Wallet

Story: Coldcard’s $100M Hack Exposes 40-Bit Entropy Flaw Across 126 Addresses

By Sakamoto Nashi

1 / 15

The Firmware Bug Behind the Breach. Francesco, co-founder of Castle Labs, pointed to the root cause: a firmware bug that dropped…

2 / 15

AI Found the Flaw in Under 20 Minutes. Here's where it gets uncomfortable for the industry.

3 / 15

A Fourth Wave May Push Losses to $130 Million. Galaxy Research isn't done counting. The team suspects a fourth wave of attacks could push total…

4 / 15

At least 15 attackers tore through Coldcard wallets and walked away with roughly $100 million. Three confirmed waves of exploitation. Possibly a fourth on the way.

5 / 15

Galaxy Digital's research team put the number together, and it's ugly. Alex Thorn, head of research at Galaxy Digital, said new victim reports kept coming in, each one…

6 / 15

Cold wallets are supposed to be the gold standard. The whole pitch is that keeping your keys off the internet protects you. The Coldcard incident kind of blows that assumption up.

7 / 15

Francesco, co-founder of Castle Labs, pointed to the root cause: a firmware bug that dropped private key entropy down to just 40 bits. Standard wallets run at 128 bits.

8 / 15

It's a reminder that cold storage security isn't just about keeping a device unplugged. The firmware running underneath matters just as much.

9 / 15

Here's where it gets uncomfortable for the industry. Haseeb Qureshi, managing partner at Dragonfly, said a $2 investment in AI hardening probably could've stopped all of this.

10 / 15

That's fast. Faster than most security audits. Faster than most bug bounty hunters would've moved.

11 / 15

See also: Coldcard Wallet Hack Tops $100M as Galaxy Research Flags 7,300 Breached Addresses

12 / 15

Not everyone's convinced, though. Tatsapat Saerejittima from Tokenomist pushed back, saying it's hard to believe AI models would've independently caught this flaw before it went…

13 / 15

But Francesco's read is more forward-looking. He thinks AI models are already cutting the time and cost it takes to find crypto vulnerabilities, and that trajectory isn't slowing…

14 / 15

Galaxy Research isn't done counting. The team suspects a fourth wave of attacks could push total losses from $100 million closer to $130 million. No confirmed timeline on that.

15 / 15

What's clear is that the three confirmed waves weren't random. Fifteen attackers, multiple rounds, 126 addresses already confirmed drained. The operation had structure.

The Currency Analytics

Want the full story?