Coldcard exploit: $100M+ stolen BTC may be hard to spend
A Coldcard exploit has led to more than $100M worth of Bitcoin (BTC) theft, according to Galaxy Research. Analyst Joe Consorti argues the attacker may struggle to move much of the loot because every stolen coin is still visible and trackable on the public blockchain.
Galaxy Research reports 1,596 BTC stolen across ~7,300 addresses in three confirmed attack waves, with potential total losses rising to 2,055 BTC (north of $130M) if suspected activity is included. Roughly 90% of the stolen BTC has reportedly not moved, and all coins from the first three confirmed waves remain in attacker-controlled wallets.
Consorti frames the event as a wallet-generation flaw, not a Bitcoin network failure. He says affected Coldcard firmware (after March 2021) produced weak seed phrases due to reduced entropy. Coinkite says the bad seeds have ~72 bits of entropy instead of the expected 128 bits, making them guessable with sufficient computing power. The company patched newer firmware but cannot change seeds already generated on vulnerable devices, urging Mk3/Mk4/Mk5/Q users to transfer funds to unaffected hardware.
A debate is ongoing over whether the stolen BTC can be laundered. Some commenters point to mixers, privacy coins, Taproot-style spending, and the Lightning Network as potential escape routes, while others believe blockchain analytics, exchange compliance, and operational mistakes would severely limit cash-out options.
At the time of writing, BTC was trading near $64,000, up ~2% in 24 hours, suggesting the market has largely separated the Coldcard exploit from Bitcoin protocol-level risk.
Neutral
Impact looks neutral for market stability. The news is about a device/wallet flaw (Coldcard exploit) rather than a break in the Bitcoin protocol, and BTC price reportedly held up (~+2% in 24h at the time). Historically, when theft events are traced to custody or wallet-side weaknesses (not consensus-layer issues), markets often digest the headline quickly after liquidity/flows look limited.
Short term: trader focus may shift toward self-custody risk controls, firmware updates, and stricter operational hygiene. Watch for volatility around any subsequent move-by-move liquidity attempts from attacker addresses.
Long term: if stolen BTC remains largely immobile (Galaxy: ~90% not moved) and analytics-driven monitoring tightens (exchanges/FBI reportedly notified), sell-pressure may be contained, reducing systemic risk. However, the ongoing debate about mixers/privacy tooling means there is still headline risk if large transfers resume.
Overall, this is a security/custody signal with monitoring implications, not an outright bearish protocol event—hence neutral.