The scale of the attack on Coldcard hardware wallets turned out to be far more serious than initially assumed. According to my analysis of fresh data, cumulative user losses have exceeded the $115 million mark. Since July 30, attackers have withdrawn 1,778.58 BTC from 8,680 addresses. This is not just a routine theft—it is a systemic failure in the security of a device that was positioned as a benchmark of reliability.
A key detail that stands out when examining on-chain data: all stolen coins were created after March 17, 2021. That is exactly when the vulnerable firmware version was released (block 674,951). No affected addresses with earlier transactions were found. This is direct proof that the problem lies in key generation on devices after this update.
Timeline and Scale of the Disaster
The average holding period of funds on drained addresses was 1,292 days—about 3.5 years. This indicates that users trusted Coldcard for long-term storage, making the losses even more painful. Notably, on August 3, I already warned about a new wave of attacks on these wallets, and now the numbers confirm the worst fears.
The breakdown of the first wave of attacks is especially telling. It accounts for $70.2 million in damages—61% of the total amount. The withdrawal speed back then stunned even Binance founder Changpeng Zhao: funds were moved within nine consecutive blocks, taking just 41 minutes. The operator paid a fixed fee of about 30 satoshis per vByte and drained one address per transaction.
In total, 1,195 wallets were affected in the first attack, and assets were split across four "collectors." For comparison, the Footprint E wave affected more addresses—2,147—but combined up to 795 vaults in a single transaction. Interestingly, most of the funds from the first wave remain untouched to this day: out of 108.65 BTC, 1,082.57 BTC are still in place.
The third wave used a different scheme: bitcoins first went to regular wallets, but now 207.73 BTC are locked in script-based "vaults." Official statements from victims lag far behind reality—only 192 people have reported losses, with their total damage amounting to 714.81 BTC (40.2% of all stolen coins). Meanwhile, individual losses reach 58.97 BTC, with a median of about 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC have not yet been linked to any owner.
My verdict: this attack is a wake-up call for the entire hardware wallet industry. Cold storage is no longer synonymous with absolute security. Coldcard users with firmware after March 2021 should immediately migrate to new devices and regenerate their keys. The incident also raises the question of the need for independent audits of random number generation in such products—trust in the manufacturer can no longer be blind.