Losses from the ongoing Coldcard Bitcoin wallet exploit have crossed $100 million, and researchers at Galaxy say the damage may not be done yet. The hack, which targets a firmware vulnerability introduced in March 2021, remains active — meaning more users could still be at risk. Galaxy warned this week that a suspected fourth wave of attacks could push total losses toward $130 million.
The firmware flaw that won't die
The bug was introduced in a firmware update back in March 2021. More than five years later, it's still live. That's an unusually long tail for a critical vulnerability in a hardware wallet, especially one marketed for its security. Galaxy Research has been tracking the exploit since it emerged, and their latest analysis suggests the attackers are not done exploiting it.
What the numbers look like
Confirmed losses have now surpassed $100 million, according to data compiled by Galaxy. The firm's researchers believe a fourth wave of attacks is underway or imminent, which could bring the total to around $130 million. The exploit appears to target a specific weakness in the Coldcard firmware that allows attackers to drain funds from affected devices.
Ripple CTO weighs in
Ripple's CTO Emeritus commented on the hack this week, though the details of his remarks were not provided in the available information. His involvement signals that the incident is drawing attention beyond the Bitcoin hardware wallet community.
Coldcard users who haven't updated their firmware since early 2021 remain vulnerable. The company has not yet released a patch that fully addresses the flaw, according to the Galaxy report. Until a fix is deployed, the window for further attacks stays open. Galaxy expects the fourth wave to materialize in the coming weeks, putting additional pressure on Coldcard to deliver a firmware update.




