The scale of the disaster with Coldcard hardware wallets turned out to be far more serious than initially assumed. According to my analysis of the latest data, the total damage to users has exceeded the $115 million mark. Starting on July 30, attackers withdrew 1,778.58 bitcoin (BTC) from 8,680 addresses. This is not just a series of targeted thefts, but a systemic attack affecting thousands of wallets.
Root of the problem: 2021 firmware
The key conclusion I drew from the latest data is that all stolen coins were created after the critical firmware update released on March 17, 2021, at block 674,951. None of the affected coins were generated before that date. This is a direct indication of a vulnerability embedded in the code. Of the 6,303 bitcoins seized, none appeared before the release, and the earliest of the 3,598 addresses reported by victims dates back to March 22, 2021.
This time boundary leaves no doubt: keys on the compromised devices existed only after the firmware release. The average "lifespan" of drained addresses was 1,292 days—about 3.5 years. Notably, as early as August 3, I warned of a new wave of attacks on wallets, and now those concerns have been fully confirmed.
Anatomy of the first wave: 61% of losses in 41 minutes
The updated statistics show that the first attack caused the most damage. It accounts for losses of $70.2 million—61% of the total amount. The withdrawal speed at the time even alarmed Binance founder Changpeng Zhao (CZ). The funds were moved across nine consecutive blocks, taking just 41 minutes. The operator paid a fixed fee of about 30 satoshis per vByte and drained one address per transaction.
In the first wave, 1,195 wallets were affected, and the withdrawn assets were split among four "collectors." By comparison, the Footprint E wave affected more addresses—2,147—and combined up to 795 vaults in a single transaction. Interestingly, most of the funds from the first wave remain untouched: of the 108.65 BTC, 1,082.57 BTC are still in place. Nearly all of Footprint E's funds—209.94 BTC—have already been moved, with only 4.38 BTC remaining.
Assets from the third wave moved under a different scheme: the bitcoins first went to regular wallets, but now 207.73 BTC are locked in "vault" scripts. Victim reports still lag behind what is visible on the blockchain. Only 192 people from the already published cases have reported losses—their total damage amounts to 714.81 BTC, or 40.2% of all stolen bitcoins.
Individual losses reach 58.97 BTC, with a median of about 1.03 BTC. Another 6,890 addresses holding 1,063.76 BTC have not yet been linked to any owner.
My verdict: this attack is a stark example of how even "impenetrable" hardware wallets can be compromised at the firmware level. Coldcard users should immediately verify the origin of their keys and consider migrating to alternative open-source solutions. The incident underscores that security is not a static product but a continuous process of auditing and updates.