News

Public · Published

Coldcard Losses Climb Past $130 Million as a Fourth Wave of Thefts Hits Self-Custody Wallets

Galaxy Research identified over 5,200 cryptocurrency addresses that lost funds after a firmware flaw in Coldcard self‑custody wallets, first reported on August 3, was exploited in a fourth wave of thefts, pushing total losses above $130 million.

Published:

Updated:

What happened

Galaxy Research identified over 5,200 cryptocurrency addresses that lost funds after a firmware flaw in Coldcard self‑custody wallets, first reported on August 3, was exploited in a fourth wave of thefts, pushing total losses above $130 million.

Confirmed

Global impact / market context

The breach shows that even hardware wallets, considered the safest crypto storage, can contain serious bugs, meaning users may lose large sums and investors could reassess the risk of self‑custody solutions for protecting digital assets.

Analyst inference

The surge to over 5,200 drained addresses highlights the growing scale of the Coldcard firmware issue, which may prompt investors to scrutinize the security track record of self‑custody wallets and consider exposure to similar vulnerabilities.

Analyst inference

What to watch

  1. Coldcard’s timeline for releasing a firmware patch and the method of distributing it to affected users, which will determine how quickly wallet security can be restored. Analyst inference
  2. Whether other wallet developers adopt AI‑assisted code review tools after Coinkite’s CEO linked the technology to discovering the Coldcard flaw, potentially improving overall code safety. Analyst inference
  3. How investors’ confidence in self‑custody solutions may shift as the number of drained addresses rises, influencing demand for alternative storage options or custodial services. Analyst inference

Evidence