The scale of damage from the series of attacks on Coldcard hardware wallets continues to shock the market. According to my analysis of blockchain data, total user losses have exceeded $115 million. Since July 30, attackers have withdrawn 1,778.58 BTC from 8,680 addresses. This is no longer just an incident—it is a systemic threat to the cold storage industry.
The key conclusion I draw from the latest data: the vulnerability has clear time boundaries. All stolen coins were created after the firmware release from March 17, 2021 (block 674,951). None of the affected coins appeared before that date. This directly points to a defect in key generation: devices flashed before the release proved invulnerable, which narrows the search for causes.
The average "lifespan" of drained addresses was 1,292 days—about 3.5 years. This suggests the attackers acted methodically, waiting years for the right moment. Notably, on August 3, I already warned of a new wave of attacks on Coldcard wallets, and those concerns have now been fully confirmed.
First Wave—The Most Devastating Blow
The greatest damage came from the first attack: $70.2 million, or 61% of the total amount. The withdrawal speed then stunned even Binance founder Changpeng Zhao (CZ). Funds were moved across nine consecutive blocks in just 41 minutes. The operator paid a fixed fee of about 30 satoshis per vByte and drained one address per transaction.
In the first wave, 1,195 wallets were affected, and the stolen assets were split among four "collectors." For comparison, the Footprint E wave affected more addresses—2,147—and combined up to 795 vaults in a single transaction. Interestingly, a significant portion of funds from the first wave remains untouched: of 108.65 BTC, 108.57 BTC are still in place. Nearly all Footprint E assets—209.94 BTC—have already been moved, with only 4.38 BTC remaining.
Assets from the third wave were moved using a different scheme: bitcoins first went to regular wallets, but now 207.73 BTC are locked in "vault" scripts. This indicates the attackers plan long-term holding rather than quick liquidation.
Notably, victim reports lag far behind reality: only 192 people have reported losses totaling 714.81 BTC—just 40.2% of all stolen coins. Individual losses reach 58.97 BTC, with a median of about 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC remain unlinked to any owner.
My verdict: this attack is a wake-up call for the entire industry. Even hardware wallets, once considered the gold standard of security, are vulnerable. I recommend all Coldcard owners check the firmware date of their devices and, at the slightest doubt, immediately transfer funds to new addresses. In current conditions, the price of caution may be measured not in dollars, but in entire fortunes.