Galaxy Reports 15 Distinct Attackers Leveraged Coldcard Security Flaw

Galaxy Reports 15 Distinct Attackers Leveraged Coldcard Security Flaw

According to Galaxy, no fewer than 15 separate attackers took advantage of the Coldcard security flaw, a breach that Dragonfly's managing partner suggests could have been prevented with minimal investment in AI-based security hardening.

No fewer than 15 separate attackers have taken advantage of the Coldcard security flaw, based on findings from Galaxy Digital's head of research, Alex Thorn, who referenced fresh victim reports that have come in following the security breach.

On Tuesday, Thorn indicated that these victim reports enabled his firm to identify additional attackers who would have otherwise remained undetected, noting that the exploit's characteristics differed significantly from breaches targeting centralized cryptocurrency exchanges.

"Due to one single victim's report of less than 1 BTC stolen, we identified a new attack with 12 BTC siphoned from 126 addresses," Thorn wrote in a Tuesday X post.

Galaxy Research estimates that losses stemming from the Coldcard vulnerability have escalated to $100 million spanning three verified attack waves. Additionally, the firm has flagged a potential fourth wave that may push aggregate losses to approximately $130 million in Bitcoin (BTC).

This continuing assault has sparked renewed discussion surrounding the security of cold storage wallet solutions and the question of whether Bitcoin holders are truly better off maintaining custody of their own assets.

$2 worth of AI hardening could have prevented the exploit: Dragonfly partner

An investment of approximately "$2 of AI hardening" could have successfully prevented the Coldcard security breach, according to Dragonfly managing partner Haseeb Qureshi, who referenced social media reports indicating that certain AI models rediscovered the vulnerability that enabled the attack in under 20 minutes.

Qureshi made these comments in response to several social media users who claimed that Claude successfully regenerated the vulnerability in a mere eight minutes. He contended that these findings might have been influenced by web search capabilities and noted that the open-source AI model GLM 5.2 managed to rediscover the attack vector in 20 minutes without web access enabled.

That said, it remains improbable that AI models would have autonomously identified this vulnerability prior to its public disclosure, according to Tatsapat Saerejittima, data lead at crypto analytics platform Tokenomist, who spoke with Cointelegraph. He said:

"The claim that AI found it in 2 mins came from a pseudonymous Reddit user who scanned the code after the vulnerability had already become public. There was no blind test, no documented methodology, and no assessment of the model's false-positive rate."

Vulnerability seen in private key setup

Francesco, co-founder of crypto research company Castle Labs, stated that the expanding capabilities of AI models are significantly lowering both the cost and time required to uncover new cryptocurrency vulnerabilities, though he emphasized that Coldcard's private key configuration may have contributed to the security weakness.

Coldcard utilized a "level of private key entropy (40 bits) much lower than the standard adopted by other wallets (a 12-word seed is 128 bits), a result of a firmware bug, making the job easier," he told Cointelegraph.

Francesco, who requested that Cointelegraph withhold his last name, indicated his expectation that the expense associated with bug discovery will continue to decline as AI models acquire additional capabilities and become increasingly prevalent in both cybersecurity defense and exploitation activities.

← Back to Blog