Skip to main content
Esc

Type to search

Articles / bitcoin-institutional / Coldcard Thefts Near $114 Million as Fourth Attack Wave Hits

Coldcard Thefts Near $114 Million as Fourth Attack Wave Hits

Total Estimated Losses
$114 million
The total estimated losses due to the Coldcard thefts since the onset of the attacks.
Total BTC Swept
1,816 BTC
The total amount of Bitcoin stolen from Coldcard wallets across all attack waves.
Victim Addresses
5,200+ addresses
The number of unique addresses affected by the Coldcard hardware wallet thefts.

§ 01 Executive Snapshot

  • What: A significant wave of thefts targeting Coldcard hardware wallets has resulted in an estimated loss of $114 million in Bitcoin.
  • Who: The attacks are linked to a firmware bug in Coldcard wallets produced by Coinkite, with notable input from Alex Thorn of Galaxy.
  • Why it matters: This event underscores vulnerabilities in hardware wallet security, potentially shaking user confidence and prompting urgent responses from manufacturers.

§ 02 Key Developments

  • Attackers have swept approximately 1,816 BTC from over 5,200 addresses since the onset of the attacks, with the latest wave accounting for 448.7 BTC from 709 addresses.
  • The thefts utilized a replace-by-fee mechanism, allowing victims a brief opportunity to transfer their funds before the attacker's transaction confirmed.
  • Coinkite has halted shipments of affected Coldcard models and released emergency firmware updates to mitigate the impact of the vulnerability.

§ 03 Strategic Context

  • The firmware bug, which went unnoticed for over five years, highlights a critical failure in hardware wallet security, a sector that promises protection against key compromise.
  • The incident occurs amidst a broader scrutiny of the hardware wallet industry, following previous high-profile thefts totaling $282 million in January due to social-engineering scams.

§ 04 Strategic Implications

  • Immediate market consequences may include heightened scrutiny and loss of trust in hardware wallet security, prompting users to reconsider their asset protection strategies.
  • Long-term implications may involve increased regulatory oversight and a push for stronger security standards in the hardware wallet industry.

§ 05 Risks & Constraints

  • Potential regulatory risks may arise as authorities investigate the security failure and its impact on consumers.
  • The ongoing threat of competitive vulnerabilities could lead to further attacks if users do not migrate their funds promptly or if security measures are inadequate.

§ 06 Watchlist / Forward Signals

  • Users are urged to migrate their funds using updated best practices immediately, as the window of vulnerability remains short.
  • Future developments will include monitoring the effectiveness of Coinkite's firmware updates and the response from users regarding their migration efforts.
§ 07

Frequently Asked Questions

What is the estimated loss from the Coldcard thefts?

The estimated loss from the Coldcard thefts is $114 million in Bitcoin.

Who is responsible for the Coldcard wallet attacks?

The attacks are linked to a firmware bug in Coldcard wallets produced by Coinkite.

How did the attackers exploit the Coldcard wallets?

The attackers utilized a replace-by-fee mechanism, allowing victims a brief opportunity to transfer their funds before the attacker's transaction confirmed.

What actions has Coinkite taken in response to the thefts?

Coinkite has halted shipments of affected Coldcard models and released emergency firmware updates to mitigate the impact of the vulnerability.

§ 08

Related Articles