In a fresh blow to the crypto community, losses from the recent Coldcard hardware wallet hack have now exceeded $100 million, according to industry analysts. Galaxy Digital has raised alarms over a possible fourth wave of attacks, suggesting that the incident may be far from over. Here’s what we know so far about the evolving situation.

The Coldcard Hack: A Recap

Coldcard, a popular brand of bitcoin hardware wallets known for its security features, was targeted by attackers who managed to compromise devices in ways previously thought unlikely. The initial breach, first reported earlier this week, has since expanded in scope, with cumulative losses crossing the nine-figure mark.

While the exact mechanism of the attack remains under investigation, early reports indicate that malicious firmware may have been injected during the supply chain process. This would allow attackers to siphon private keys from devices before users even activated them, making detection extremely difficult.

How the Attack Unfolded

  • Attackers may have intercepted shipments and replaced legitimate firmware with compromised versions.
  • Users unknowingly used compromised devices, assuming they were secure.
  • The stolen keys enabled attackers to drain bitcoin from wallets, with losses mounting over multiple days.

Galaxy Digital's research team has been tracking the outflow of funds, noting unusual patterns that suggest the attackers are moving funds in a systematic manner, possibly preparing for additional strikes.

Galaxy Flags Possible Fourth Wave

In a note to clients, Galaxy Digital analysts highlighted the possibility of a fourth wave of attacks. This follows three distinct phases of exploitation already observed, each targeting different user groups or wallet types.

The first wave reportedly focused on early adopters who had purchased Coldcard devices from the official store. The second wave expanded to include devices bought through authorized resellers, while the third wave involved users who had updated their firmware from a compromised source.

Now, Galaxy warns that a fourth wave could target users who have not yet updated their wallets or who are still using devices from the affected batch. The exact criteria for this potential wave are not yet clear, but the warning is a stark reminder that the incident is not yet contained.

What Users Should Do Right Now

  • If you own a Coldcard device, check the serial number and firmware version against the list of affected units published by the manufacturer.
  • Do not connect your Coldcard to any computer until you have verified its integrity using the official verification tools.
  • Consider moving funds to a new wallet with a different hardware brand as a precaution.

Security experts emphasize that this is a rapidly evolving situation and that users should stay tuned to official Coldcard announcements for the latest guidance.

Market Impact and Community Response

The news has sent ripples through the crypto community, with many questioning the security of hardware wallets in general. While no major exchange has reported a direct impact, the overall sentiment has turned cautious, and some traders are moving funds to exchanges or custodial services in the interim.

Coldcard's parent company, Coinkite, has issued a statement acknowledging the breach and promising to cooperate with law enforcement. They have also urged affected users to report any losses to their support team, though they caution that reimbursement is not guaranteed.

Galaxy's report suggests that the attackers are likely a well-funded and highly sophisticated group, possibly with state sponsorship, given the scale and precision of the operation. This has led to calls for increased regulation and security standards in the hardware wallet industry.

Lessons Learned: The Need for Vigilance

This incident serves as a sobering reminder that no device is 100% secure, especially when supply chains are involved. Experts recommend that users adopt a defense-in-depth approach, using multiple layers of security such as multi-signature wallets and cold storage with air-gapped signing.

For now, the focus remains on mitigating the damage and preventing further losses. The crypto community is watching closely as the story develops, and many are calling for transparency from all parties involved.

Key Takeaways

  • Coldcard hack losses have surpassed $100 million, making it one of the largest hardware wallet breaches in history.
  • Galaxy Digital warns of a possible fourth wave of attacks, urging users to take immediate action.
  • The attack may have originated from compromised firmware during the supply chain, affecting devices before they reached users.
  • Users should verify their devices, move funds if necessary, and consider additional security measures.
  • This event highlights the importance of rigorous supply chain security and user vigilance in the crypto space.