Coldcard Hackers Multiply Like Wallets at a Crypto Conference 🪙
At least 15 distinct attackers have exploited a Coldcard hardware-wallet vulnerability, according to Galaxy Digital head of research Alex Thorn, who said Tuesday that fresh victim reports allowed Galaxy to identify perpetrators who would otherwise have remained hidden. Thorn wrote on X that "due to one single victim's report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses," underscoring how the nature of the exploit differed from a centralized-exchange breach. Galaxy Research estimates losses have reached $100 million across three confirmed attack waves, with a suspected fourth wave that could push totals to roughly $130 million in Bitcoin ($BTC). The campaign has reignited debate over the security of cold storage and whether self-custody truly reduces user risk.
Dragonfly managing partner Haseeb Qureshi wrote that roughly "$2 of AI hardening" could have prevented the exploit, citing social media claims that artificial-intelligence models rediscovered the underlying vulnerability in under 20 minutes. Qureshi noted that some users reported Claude regenerating the flaw in eight minutes, while the open-source model GLM 5.2 reproduced it in 20 minutes with web access disabled, though he cautioned the Claude results may have been contaminated by web search. Tokenomist data lead Tatsapat Saerejittima pushed back on those claims, telling Cointelegraph: "The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model's false-positive rate."
Castle Labs co-founder Francesco said AI is accelerating the discovery of crypto vulnerabilities and pointed to Coldcard's private-key setup as a contributing factor, telling Cointelegraph the device "used a level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug, making the job easier." Francesco, who asked that his last name be omitted, added that he expects the cost of bug discovery to continue falling as AI models gain broader use in both cybersecurity and offensive exploits. Cointelegraph reported separately that Dragonfly partner Qureshi has argued AI has not triggered a DeFi "hackpocalypse."
Mentioned Coins
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.