Canadian Bitcoin holders make up a quarter of all attributable losses in the Coldcard wallet exploit, according to new analysis from Galaxy Research. The total stolen assets across the incident have reached $116 million, making it one of the costliest hardware wallet breaches on record. Galaxy traced the root cause to a malicious firmware update pushed in March 2021.
The Canadian connection
Galaxy's data shows that 25% of the victims whose losses can be tied to a specific country are Canadian. That's a far higher share than Canada's roughly 4-5% of global Bitcoin ownership, suggesting the attack may have been targeted or that Canadian users were disproportionately affected by the compromised firmware. The researchers did not name specific individuals or exchanges involved.
Tracing the attack
The exploit originated from a firmware update released by Coldcard in March 2021. Galaxy Research says the malicious code was inserted into the update, allowing attackers to siphon funds from wallets that applied the patch. The total $116 million figure includes both direct theft and subsequent losses tied to the compromised keys. Coldcard has since issued a fix, but the damage was already done.
What users should know
Coldcard users who updated their firmware in March 2021 and later lost funds should check if their wallets were affected. The company has published a tool to verify whether a specific device was compromised. Galaxy recommends that any user who suspects exposure rotate their seed phrase and move funds to a new wallet. The investigation is ongoing, and Galaxy says it will release more details as they become available.




