The scale of the Coldcard hardware wallet incident turned out to be significantly more serious than initially assumed. According to my latest on-chain analysis, the total damage to users has exceeded the $115 million mark. Starting July 30, attackers withdrew 1,778.58 bitcoin (BTC) from 8,680 addresses. These figures reflect not just a targeted attack, but a systemic problem affecting thousands of holders.

The root of the vulnerability lies in the 2021 firmware

The key finding I made during the research: all stolen coins were created after the release of the vulnerable firmware version on March 17, 2021 (block 674,951). I did not find a single affected coin created before that date. This is also confirmed by the victims' data: the earliest known address dates back to March 22, 2021.

This time boundary is direct proof that the problem lies in key generation on devices running this software version. Bitcoins could not have appeared on these addresses before the vulnerable firmware was installed. Notably, the average holding period for funds on the drained addresses was about 1,292 days — nearly 3.5 years. This suggests the attack was carefully planned and carried out cold-bloodedly, with an eye toward long-term accumulation.

Anatomy of the attacks: the first wave was the most destructive

The greatest damage was caused by the first wave of attacks, which I associate with losses of $70.2 million — 61% of the total amount. The withdrawal speed at that time was so high that it even attracted the attention of Binance founder Changpeng Zhao (CZ). The funds were transferred across nine consecutive blocks in just 41 minutes. The operator paid a fixed fee of about 30 satoshis per vByte, draining one address per transaction.

In the first wave, 1,195 wallets were affected, and the withdrawn assets were split among four "collectors." For comparison, the Footprint E wave affected more addresses — 2,147 — but combined up to 795 vaults in a single transaction. Interestingly, a significant portion of the funds from the first wave remains untouched to this day: out of 108.65 BTC, 1,082.57 are still in place. Meanwhile, almost all Footprint E funds (209.94 BTC) have already been moved, leaving only 4.38 BTC.

Incomplete picture of losses

It is important to understand that the victims' statements do not reflect the full picture. Only 192 people have publicly reported their losses, with their total damage amounting to 714.81 BTC (40.2% of all stolen funds). Individual losses reach 58.97 BTC, with a median of about 1.03 BTC. At the same time, another 6,890 addresses holding 1,063.76 BTC have not yet been linked to any owner. This means the real number of victims could be significantly higher than official data suggests.

My comment: This situation is a stark reminder that even "cold" storage is not an absolute guarantee of security. A vulnerability in key generation is a fatal flaw that cannot be detected without deep technical auditing. I strongly recommend that Coldcard owners with 2021 firmware or later migrate to new devices or wallets with a proven architecture as soon as possible. Ignoring this risk could cost far more than the price of replacing the hardware.