Coldcard Bitcoin exploit hits $88.6M as wallets keep getting drained
The Coldcard Bitcoin exploit is still ongoing, according to Galaxy Research, which says a third wave of sweeps has pushed observed losses to about 1,367 BTC (~$88.6M) across 4,585 addresses. In this latest wave, 207.73 BTC was drained to attacker-controlled wallets.
Galaxy’s Alex Thorn called the transfers “deliberate” and likely programmatic, possibly orchestrated with an LLM. He warned that every single-signature Coldcard address created after the March 2021 firmware flaw will eventually be emptied, even if funds have sat untouched for years (average dormancy cited: 3.18 years).
The firm also flagged roughly 600 suspected attacker addresses to federal investigators and compliance/cyber-investigation partners, based on victims sharing transaction details that helped map on-chain patterns.
The Coldcard Bitcoin exploit stems from a March 2021 Coinkite firmware randomness error that made seed phrases generate private keys that were easier to guess. Despite security best practices, victims reported being swept quickly even when their Coldcard devices were not connected to the internet.
Traders should note the market reaction risk: the breach has triggered an unusual rush to move BTC off self-custody and back onto centralized exchanges (e.g., Coinbase, Binance), potentially increasing sell pressure from affected long-term holders in the short term.
Bearish
This is likely bearish for near-term sentiment because the Coldcard Bitcoin exploit is still active and the theft totals are rising. Even though this is not a protocol-level Bitcoin failure, it forces real BTC holders (often long-term) to reassess custody, creating a higher probability of sell pressure as victims move funds back to centralized exchanges.
In similar past incidents—when large, well-documented wallet compromises occurred—market impact typically showed up as short-term volatility and liquidity shifts toward exchanges, followed by stabilization after the immediate outflows slowed. Here, Galaxy reports multiple “waves” and warns that any single-sig Coldcard address generated after the March 2021 flaw could be drained eventually, which can extend fear and keep traders and holders in a defensive posture.
Longer term, the effect may fade if no further large, unexpected losses appear beyond the identified set and if exchanges and investigators can process funds smoothly. But until the drain clearly stops, risk premiums around custody and hardware wallets may remain elevated, which can weigh on sentiment.