$115 Million Lost in Coldcard Wallet Hack, According to Galaxy Research

banner-image

Analysts describe a years-long campaign targeting users of the hardware wallet, according to a new Galaxy Research report.

Galaxy Research has published an estimate placing losses from a Coldcard wallet hack above $115 million. The figure was reported by Bitcoin Magazine and CoinTurk News, both citing the research firm's findings. AMBCrypto's coverageframed the exploit as part of a theft campaign stretching back years, rather than a single recent event.

Coldcard is a hardware wallet designed to store Bitcoin private keys offline. Hardware wallets are widely used by security-conscious holders because they keep signing keys away from internet-connected devices. That design is meant to reduce exposure to remote hacking and malware. A breach of this scale raises questions about how the underlying vulnerability was exploited and for how long it went unnoticed.

The scale of the reported losses is notable given the device's reputation within the Bitcoin community. Cold storage solutions like Coldcard are often recommended specifically because they promise stronger protection than software wallets or exchange custody. A theft campaign of this size, if confirmed in full detail, would represent one of the larger hardware wallet-related losses reported in recent years.

AMBCrypto's reporting suggests the exploit was not a single, quickly executed attack. Instead, it appears to describe a pattern of theft occurring over an extended period. That framing implies attackers may have found a method that could be repeated across multiple victims without immediate detection. Details on the precise mechanism, whether tied to a firmware flaw, supply chain issue, or user-side error, were not fully specified across the available reporting.

Galaxy Research is known for producing market and security analysis within the digital asset industry. Its estimates are frequently cited by other outlets covering crypto security incidents. The firm's $115 million figure has now been referenced by multiple publications, though the underlying methodology for calculating losses has not been detailed in full.

Hardware wallet security has come under scrutiny before, following past incidents involving other device makers. Users and custody providers have periodically had to reassess assumptions about offline storage after vulnerabilities emerged. This latest reported figure adds to a broader conversation about how much trust the industry places in any single security model, hardware or otherwise.

For now, the reported losses stand as an estimate from a single research entity, even as the story has been picked up across several outlets. Confirmation of the exact cause, affected user count, and timeline may take further investigation. Coldcard's manufacturer has not been quoted directly in the available reporting responding to the findings.

Market Impact

A confirmed loss figure above $115 million could renew scrutiny of hardware wallet security practices across the Bitcoin custody industry. Investors and institutions relying on cold storage may reassess vendor risk, firmware update procedures, and supply chain safeguards in light of the report.

The broader market impact is likely to be reputational rather than immediately reflected in Bitcoin's price, given the isolated nature of the reported theft relative to total Bitcoin circulation. However, sustained attention to the story could pressure hardware wallet makers generally to publish clearer security disclosures.

The Galaxy Research estimate underscores that even offline storage solutions carry security risks that can accumulate unnoticed over time. Further details on the exploit's mechanism and scope are likely to shape how the industry responds.

Frequently Asked Questions

What is Coldcard?

Coldcard is a hardware wallet used to store Bitcoin private keys offline, designed to reduce exposure to remote hacking.

How much was reportedly lost in the hack?

Galaxy Research estimated losses have surpassed $115 million, according to reporting from Bitcoin Magazine and CoinTurk News.

Was this a single attack or an ongoing campaign?

AMBCrypto's reporting described the exploit as part of a theft campaign that appears to have unfolded over several years, rather than one isolated incident.

Has Coldcard's manufacturer responded to the report?

The available reporting does not include a direct response from Coldcard's manufacturer regarding the findings.