The scale of damage from the series of attacks on Coldcard hardware wallets turned out to be far more serious than previously assumed. According to my analysis of blockchain data, total user losses have exceeded the $115 million mark. Between July 30, attackers withdrew 1,778.58 bitcoins (BTC) from 8,680 addresses. This is the final figure, which includes all waves of attacks recorded over recent months.
A key detail that stands out when examining on-chain data: virtually all stolen coins were created after March 17, 2021 — that is when the vulnerable firmware version was released at block 674,951. I found no affected address with coins generated before that date. This is direct proof that the root of the problem lies in key generation on devices with defective software.
The average holding period of funds on drained addresses was about 1,292 days — roughly 3.5 years. This indicates the attack was carefully planned: attackers waited for years until users accumulated significant sums before striking.
First wave — the most devastating blow
The greatest damage came from the first wave of attacks, which cost users $70.2 million — 61% of the total losses. The speed of fund withdrawal at that time was so high that it even drew the attention of Binance founder Changpeng Zhao (CZ). Funds were moved across nine consecutive blocks in just 41 minutes, with the operator paying a fixed fee of about 30 satoshis per vByte and draining one address per transaction.
Interestingly, the first wave affected 1,195 wallets, and the stolen assets were divided among four "collectors." For comparison, the Footprint E wave affected more addresses — 2,147 — and combined up to 795 vaults in a single transaction.
Notably, a significant portion of funds from the first wave remained untouched: out of 108.65 BTC, 108.57 BTC are still in place. Nearly all Footprint E funds — 209.94 BTC — have already been moved, with only 4.38 BTC remaining.
Uneven distribution and undisclosed losses
Assets from the third wave moved under a different pattern: bitcoins first went to regular wallets, but now 207.73 BTC are locked in vault scripts. Victim reports still lag behind what is visible on the blockchain. Only 192 people from already published cases have reported losses — their combined damage amounted to 714.81 BTC, or 40.2% of all stolen bitcoins.
Individual losses reach up to 58.97 BTC, with a median of about 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC are not yet linked to any owner. This means the real number of victims could be significantly higher than official figures.
My comment: This situation is a wake-up call for the entire hardware wallet industry. Even "cold" storage is not a panacea if the firmware contains a critical vulnerability. Users should verify the origin of their devices and update software only from official sources, as well as diversify storage of large sums across multiple independent wallets.