A third wave of attacks on Coldcard hardware wallet users has added 1,367 Bitcoin across 4,585 addresses to the theft total, reaching $88.6 million, according to Galaxy Research's analysis released August 1.

The exploit appears to follow a pattern of successive compromise events rather than a single coordinated breach. Galaxy Research identified three distinct waves of fund transfers from compromised wallets, with each wave targeting fresh batches of addresses. The mechanism and initial vector of the Coldcard compromise remain under investigation.

Across total value locked, last 90 days
Across total value locked, last 90 days · MSB Intel data desk

Coldcard hardware wallets are designed to hold cryptocurrency offline, isolating private keys from internet-connected devices. The device is manufactured by Coinkite, a Canadian firm that has shipped thousands of units since 2015. Access to this many addresses points to either a flaw in the device's firmware, a supply-chain intervention, or a social engineering attack targeting wallet recovery phrases.

MSB Intel

The losses span three geographically distributed attack waves, each adding incrementally to the total. The spread across 4,585 separate addresses indicates the attacker or attackers gained access to multiple wallets, each potentially belonging to different users. This pattern differs from typical exchange hacks, which consolidate stolen funds into fewer high-value addresses.

Hardware wallet compromises are rare relative to exchange breaches, making this event unusual in scale for the category. Coinkite has not yet issued a public statement addressing the exploit or confirming whether a firmware vulnerability or physical tampering is responsible. The company's response and any recommended user actions could determine whether additional waves of theft occur.

Galaxy Research's findings place the total losses at $88.6 million after the third wave, a figure that assumes no further compromises occur. If the pattern continues, the total could exceed $100 million. Three separate events have unfolded in a span of days, with attackers retaining access to additional compromised wallets not yet liquidated.

The verification of Coldcard's security posture will be critical to determining whether affected users can recover their remaining funds. If the breach stems from firmware, a patch could prevent further losses from newly addressed wallets; if the attack vector is physical or supply-chain based, existing hardware in the field may remain vulnerable regardless of software updates.