What happened
Galaxy Digital's head of research, Alex Thorn, says the investigation into the Coldcard hardware wallet exploit has expanded, with at least 15 separate attackers now identified. The update follows new victim reports that surfaced after the incident, according to a Cointelegraph report.
Why it matters for the market
Thorn noted that victim-supplied information helped researchers uncover attack activity that had not been previously flagged. Because this type of exploit differs from centralized exchange thefts, linking the attackers relies heavily on on-chain analysis and victim feedback.
One victim reported losing less than 1 BTC, and that tip led the team to identify a previously unknown attack that drained roughly 12 BTC from 126 addresses. Galaxy Research had earlier estimated that the Coldcard vulnerability was behind at least three rounds of thefts totaling about $100 million in bitcoin. The firm also suspects a fourth round, which could push total losses to around $130 million.
The incident has also reignited debate over bitcoin self-custody security. Dragonfly managing partner Haseeb Qureshi suggested that around $2 worth of AI-assisted security hardening might have prevented the vulnerability, and said some AI models could rediscover the bug in a relatively short time. However, industry observers caution that such claims about AI speed lack rigorous blind testing and verification.
What traders should watch
Researchers argue that as AI models improve, the cost of finding vulnerabilities and launching attacks in crypto could keep falling, putting more pressure on wallet developers to strengthen code audits and security safeguards.