My latest on-chain data analysis has revealed an alarming picture: the cumulative losses of Coldcard hardware wallet users have reached $115 million. Since July 30, attackers have withdrawn 1,778.58 BTC from 8,680 addresses. These are not just numbers—this is a systemic security failure that demands the close attention of the entire crypto community.
The key conclusion I have drawn from the fresh data is that all stolen coins were created after March 17, 2021, when the vulnerable firmware version was released (block 674,951). Not a single affected coin was generated earlier. This is direct proof that the problem lies precisely in the software, not in random user errors.
Timeline of attacks and scale of damage
The analysis shows that most of the drained addresses had existed for an average of 1,292 days—about 3.5 years. This suggests that the attackers acted patiently, waiting for the moment when owners would let their guard down. The first wave of attacks turned out to be the most destructive: it accounts for $70.2 million, or 61% of all losses. Funds were withdrawn at an alarming speed—41 minutes for nine consecutive blocks, with a fixed fee of about 30 satoshis per vByte.
Interestingly, of the 6,303 bitcoins seized, none appeared before the release of the vulnerable firmware. This confirms my hypothesis: keys on the affected devices became vulnerable only after the update. At the same time, only 192 people have officially reported their losses (total damage of 714.81 BTC), which amounts to just 40.2% of all stolen funds. The remaining 6,890 addresses with 1,063.76 BTC remain unidentified.
My conclusions
This situation is a wake-up call for the entire hardware wallet industry. Even the most reliable devices are not immune to firmware errors. I recommend that all Coldcard holders, especially those who used devices before 2021, immediately check their assets and consider migrating to new models with updated software. In a world where hackers are becoming increasingly sophisticated, vigilance is the only true defense.